CVE-2020-7523
https://notcve.org/view.php?id=CVE-2020-7523
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is invoked. The driver does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. Se presenta una vulnerabilidad de Administración de Privilegios Inapropiada en Schneider Electric Modbus Serial Driver (consulte la notificación de seguridad para las versiones) que podría causar una escalada de privilegios locales cuando el servicio Modbus Serial Driver es invocado. El controlador no asigna, modifica, rastrea o comprueba apropiadamente los privilegios de un actor, creando una esfera de control no prevista para ese actor • https://www.se.com/ww/en/download/document/SEVD-2020-224-01 • CWE-269: Improper Privilege Management •
CVE-2020-7522 – Schneider Electric APC Easy UPS Online SoundUploadServlet processRequest Directory Traversal Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-7522
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `SoundUploadServlet` which may lead to uploading executable files to non-specified directories. Se presenta una vulnerabilidad de Limitación Inapropiada de un Nombre de Ruta en un Directorio Restringido ("Path Traversal") en SFAPV9601 - APC Easy UPS On-Line Software (versiones V2.0 y anterior) cuando se accede a un método vulnerable de "SoundUploadServlet" puede conllevar a una carga de archivos ejecutables hacia directorios no especificados This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric APC Easy UPS Online. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SoundUploadServlet class. When parsing the filename parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. • https://www.se.com/ww/en/download/document/SEVD-2020-224-04 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2020-7521 – Schneider Electric APC Easy UPS Online FileUploadServlet processRequest Directory Traversal Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-7521
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `FileUploadServlet` which may lead to uploading executable files to non-specified directories. Se presenta una vulnerabilidad de Limitación Inapropiada de un Nombre de Ruta en un Directorio Restringido ("Path Traversal") en SFAPV9601 - APC Easy UPS On-Line Software (versiones V2.0 y anteriores) cuando se accede a un método vulnerable de "FileUploadServlet" puede conllevar a una carga de archivos ejecutables hacia directorios no especificados This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric APC Easy UPS Online. Authentication is not required to exploit this vulnerability. The specific flaw exists within the FileUploadServlet class. When parsing the filename parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. • https://www.se.com/ww/en/download/document/SEVD-2020-224-04 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2020-7519
https://notcve.org/view.php?id=CVE-2020-7519
A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account. CWE-521: Se presenta una vulnerabilidad de Requisitos de Contraseña débil en Easergy Builder (Versión 1.4.7.2 y anteriores) que podría permitir a un atacante comprometer una cuenta de usuario • https://www.se.com/ww/en/download/document/SEVD-2020-161-05 • CWE-521: Weak Password Requirements •
CVE-2020-7518
https://notcve.org/view.php?id=CVE-2020-7518
A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify project configuration files. A CWE-20: Se presenta una vulnerabilidad de comprobación de entrada inapropiada en Easergy Builder (Versión 1.4.7.2 y anteriores) que podría permitir a un atacante modificar los archivos de configuración del proyecto • https://www.se.com/ww/en/download/document/SEVD-2020-161-05 • CWE-20: Improper Input Validation •