Impact
This vulnerability exists in the getupsvar() function of apcupsd, where uninitialized stack memory can be printed into an HTTP response. The bug occurs when a STATUS line contains fewer than three whitespace‑separated tokens; the sscanf call assigns no value, yet the caller assumes a successful parse and outputs the uninitialized buffer. The result is that arbitrary, uninitialized data may be sent to a requesting client, leaking internal data or sensitive information.
Affected Systems
apcupsd version 3.14.14 and earlier. The bug is present in all CGI scripts that call getupsvar(), namely upsstats.cgi, multimon.cgi, and upsfstats.cgi. Users running apcupsd on any platform that exposes these CGI endpoints are potentially susceptible.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires reaching the affected CGI scripts over HTTP, which is common for web‑based UPS monitoring interfaces. An attacker who can craft a request that triggers the parsing logic can obtain the uninitialized data in the response, potentially revealing internal state or configuration details.
OpenCVE Enrichment