A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior / SMT Series ID=1040: UPS 01.2 and prior / SMT Series ID=1031: UPS 03.1 and prior), SMC Series (SMC Series ID=1005: UPS 14.1 and prior / SMC Series ID=1007: UPS 11.0 and prior / SMC Series ID=1041: UPS 01.1 and prior), SCL Series (SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior), SMX Series (SMX Series ID=20: UPS 10.2 and prior / SMX Series ID=23: UPS 07.0 and prior), SRT Series (SRT Series ID=1010/1019/1025: UPS 08.3 and prior / SRT Series ID=1024: UPS 01.0 and prior / SRT Series ID=1020: UPS 10.4 and prior / SRT Series ID=1021: UPS 12.2 and prior / SRT Series ID=1001/1013: UPS 05.1 and prior / SRT Series ID=1002/1014: UPSa05.2 and prior), APC SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC Series ID=1018: UPS 04.2 and prior), SMTL Series (SMTL Series ID=1026: UPS 02.9 and prior), SCL Series (SCL Series ID=1029: UPS 02.5 and prior / SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior / SCL Series ID=1037: UPS 03.1 and prior), SMX Series (SMX Series ID=1031: UPS 03.1 and prior)

Project Subscriptions

Vendors Products
Schneider-electric Subscribe
Scl Series 1029 Ups Subscribe
Scl Series 1029 Ups Firmware Subscribe
Scl Series 1030 Ups Subscribe
Scl Series 1030 Ups Firmware Subscribe
Scl Series 1036 Ups Subscribe
Scl Series 1036 Ups Firmware Subscribe
Scl Series 1037 Ups Subscribe
Scl Series 1037 Ups Firmware Subscribe
Smc Series 1005 Ups Subscribe
Smc Series 1005 Ups Firmware Subscribe
Smc Series 1007 Ups Subscribe
Smc Series 1007 Ups Firmware Subscribe
Smc Series 1018 Ups Subscribe
Smc Series 1018 Ups Firmware Subscribe
Smc Series 1041 Ups Subscribe
Smc Series 1041 Ups Firmware Subscribe
Smt Series 1015 Ups Subscribe
Smt Series 1015 Ups Firmware Subscribe
Smt Series 1031 Ups Subscribe
Smt Series 1031 Ups Firmware Subscribe
Smt Series 1040 Ups Subscribe
Smt Series 1040 Ups Firmware Subscribe
Smt Series 18 Ups Subscribe
Smt Series 18 Ups Firmware Subscribe
Smtl Series 1026 Ups Subscribe
Smtl Series 1026 Ups Firmware Subscribe
Smx Series 1031 Ups Subscribe
Smx Series 1031 Ups Firmware Subscribe
Smx Series 20 Ups Subscribe
Smx Series 20 Ups Firmware Subscribe
Smx Series 23 Ups Subscribe
Smx Series 23 Ups Firmware Subscribe
Srt Series 1001 Ups Subscribe
Srt Series 1001 Ups Firmware Subscribe
Srt Series 1002 Ups Subscribe
Srt Series 1002 Ups Firmware Subscribe
Srt Series 1010 Ups Subscribe
Srt Series 1010 Ups Firmware Subscribe
Srt Series 1013 Ups Subscribe
Srt Series 1013 Ups Firmware Subscribe
Srt Series 1014 Ups Subscribe
Srt Series 1014 Ups Firmware Subscribe
Srt Series 1019 Ups Subscribe
Srt Series 1019 Ups Firmware Subscribe
Srt Series 1020 Ups Subscribe
Srt Series 1020 Ups Firmware Subscribe
Srt Series 1021 Ups Subscribe
Srt Series 1021 Ups Firmware Subscribe
Srt Series 1025 Ups Subscribe
Srt Series 1025 Ups Firmware Subscribe
Srtl1000rmxli Subscribe
Srtl1000rmxli-nc Subscribe
Srtl1000rmxli-nc Firmware Subscribe
Srtl1000rmxli Firmware Subscribe
Srtl1500rmxli Subscribe
Srtl1500rmxli-nc Subscribe
Srtl1500rmxli-nc Firmware Subscribe
Srtl1500rmxli Firmware Subscribe
Srtl2200rmxli Subscribe
Srtl2200rmxli-nc Subscribe
Srtl2200rmxli-nc Firmware Subscribe
Srtl2200rmxli Firmware Subscribe
Srtl3000rmxli Subscribe
Srtl3000rmxli-nc Subscribe
Srtl3000rmxli-nc Firmware Subscribe
Srtl3000rmxli Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-15790 A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior / SMT Series ID=1040: UPS 01.2 and prior / SMT Series ID=1031: UPS 03.1 and prior), SMC Series (SMC Series ID=1005: UPS 14.1 and prior / SMC Series ID=1007: UPS 11.0 and prior / SMC Series ID=1041: UPS 01.1 and prior), SCL Series (SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior), SMX Series (SMX Series ID=20: UPS 10.2 and prior / SMX Series ID=23: UPS 07.0 and prior), SRT Series (SRT Series ID=1010/1019/1025: UPS 08.3 and prior / SRT Series ID=1024: UPS 01.0 and prior / SRT Series ID=1020: UPS 10.4 and prior / SRT Series ID=1021: UPS 12.2 and prior / SRT Series ID=1001/1013: UPS 05.1 and prior / SRT Series ID=1002/1014: UPSa05.2 and prior), APC SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC Series ID=1018: UPS 04.2 and prior), SMTL Series (SMTL Series ID=1026: UPS 02.9 and prior), SCL Series (SCL Series ID=1029: UPS 02.5 and prior / SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior / SCL Series ID=1037: UPS 03.1 and prior), SMX Series (SMX Series ID=1031: UPS 03.1 and prior)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-02T23:40:03.366Z

Reserved: 2022-02-21T00:00:00

Link: CVE-2022-0715

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-09T20:15:08.300

Modified: 2024-11-21T06:39:14.900

Link: CVE-2022-0715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses