// For flags

CVE-2022-0715

 

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior / SMT Series ID=1040: UPS 01.2 and prior / SMT Series ID=1031: UPS 03.1 and prior), SMC Series (SMC Series ID=1005: UPS 14.1 and prior / SMC Series ID=1007: UPS 11.0 and prior / SMC Series ID=1041: UPS 01.1 and prior), SCL Series (SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior), SMX Series (SMX Series ID=20: UPS 10.2 and prior / SMX Series ID=23: UPS 07.0 and prior), SRT Series (SRT Series ID=1010/1019/1025: UPS 08.3 and prior / SRT Series ID=1024: UPS 01.0 and prior / SRT Series ID=1020: UPS 10.4 and prior / SRT Series ID=1021: UPS 12.2 and prior / SRT Series ID=1001/1013: UPS 05.1 and prior / SRT Series ID=1002/1014: UPSa05.2 and prior), APC SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC Series ID=1018: UPS 04.2 and prior), SMTL Series (SMTL Series ID=1026: UPS 02.9 and prior), SCL Series (SCL Series ID=1029: UPS 02.5 and prior / SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior / SCL Series ID=1037: UPS 03.1 and prior), SMX Series (SMX Series ID=1031: UPS 03.1 and prior)

Una CWE-287: Se presenta una vulnerabilidad de autenticación inapropiada que podría causar que un atacante cambie arbitrariamente el comportamiento del SAI cuando es filtrada una clave y es usada para cargar firmware malicioso. Producto afectado: Familia de Smart-UPS de APC: Serie SMT (SMT Series ID=18: UPS versiones 09.8 y anteriores / SMT Series ID=1040: UPS versiones 01.2 y anteriores / SMT Series ID=1031: UPS versiones 03.1 y anteriores), SMC Series (SMC Series ID=1005: UPS versiones 14.1 y anteriores / SMC Series ID=1007: UPS versiones 11.0 y anteriores / SMC Series ID=1041: UPS versiones 01.1 y anteriores), SCL Series (SCL Series ID=1030: UPS versiones 02.5 y anteriores / SCL Series ID=1036: UPS versiones 02.5 y anteriores), SMX Series (SMX Series ID=20: UPS versiones 10.2 y anteriores / SMX Series ID=23: UPS versiones 07.0 y anteriores), SRT Series (SRT Series ID=1010/1019/1025: UPS versiones 08.3 y anteriores / SRT Series ID=1024: UPS versiones 01.0 y anteriores / SRT Series ID=1020: UPS versiones 10.4 y anteriores / SRT Series ID=1021: UPS versiones 12.2 y anteriores / SRT Series ID=1001/1013: UPS versiones 05.1 y anteriores / SRT Series ID=1002/1014: UPS versiones a05.2 y anteriores), Familia SmartConnect de APC: Serie SMT (Serie SMT ID=1015: UPS versiones 04.5 y anteriores), Serie SMC (Serie SMC ID=1018: UPS versiones 04.2 y anteriores), Serie SMTL (Serie SMTL ID=1026: UPS versiones 02.9 y anteriores), Serie SCL (Serie SCL ID=1029: UPS versiones 02.5 y anteriores / SCL Series ID=1030: UPS versiones 02.5 y anteriores / SCL Series ID=1036: UPS versiones 02.5 y anteriores / SCL Series ID=1037: UPS versiones 03.1 y anteriores), SMX Series (SMX Series ID=1031: UPS versiones 03.1 y anteriores)

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-02-21 CVE Reserved
  • 2022-03-09 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-11-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
  • CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Schneider-electric
Search vendor "Schneider-electric"
Smt Series 1015 Ups Firmware
Search vendor "Schneider-electric" for product "Smt Series 1015 Ups Firmware"
<= 04.5
Search vendor "Schneider-electric" for product "Smt Series 1015 Ups Firmware" and version " <= 04.5"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smt Series 1015 Ups
Search vendor "Schneider-electric" for product "Smt Series 1015 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Smc Series 1018 Ups Firmware
Search vendor "Schneider-electric" for product "Smc Series 1018 Ups Firmware"
<= 04.2
Search vendor "Schneider-electric" for product "Smc Series 1018 Ups Firmware" and version " <= 04.2"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smc Series 1018 Ups
Search vendor "Schneider-electric" for product "Smc Series 1018 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Smtl Series 1026 Ups Firmware
Search vendor "Schneider-electric" for product "Smtl Series 1026 Ups Firmware"
<= 02.9
Search vendor "Schneider-electric" for product "Smtl Series 1026 Ups Firmware" and version " <= 02.9"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smtl Series 1026 Ups
Search vendor "Schneider-electric" for product "Smtl Series 1026 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1029 Ups Firmware
Search vendor "Schneider-electric" for product "Scl Series 1029 Ups Firmware"
<= 02.5
Search vendor "Schneider-electric" for product "Scl Series 1029 Ups Firmware" and version " <= 02.5"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1029 Ups
Search vendor "Schneider-electric" for product "Scl Series 1029 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1030 Ups Firmware
Search vendor "Schneider-electric" for product "Scl Series 1030 Ups Firmware"
<= 02.5
Search vendor "Schneider-electric" for product "Scl Series 1030 Ups Firmware" and version " <= 02.5"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1030 Ups
Search vendor "Schneider-electric" for product "Scl Series 1030 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1036 Ups Firmware
Search vendor "Schneider-electric" for product "Scl Series 1036 Ups Firmware"
<= 02.5
Search vendor "Schneider-electric" for product "Scl Series 1036 Ups Firmware" and version " <= 02.5"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1036 Ups
Search vendor "Schneider-electric" for product "Scl Series 1036 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1037 Ups Firmware
Search vendor "Schneider-electric" for product "Scl Series 1037 Ups Firmware"
<= 03.1
Search vendor "Schneider-electric" for product "Scl Series 1037 Ups Firmware" and version " <= 03.1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1037 Ups
Search vendor "Schneider-electric" for product "Scl Series 1037 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Smx Series 1031 Ups Firmware
Search vendor "Schneider-electric" for product "Smx Series 1031 Ups Firmware"
<= 03.1
Search vendor "Schneider-electric" for product "Smx Series 1031 Ups Firmware" and version " <= 03.1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smx Series 1031 Ups
Search vendor "Schneider-electric" for product "Smx Series 1031 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Smt Series 18 Ups Firmware
Search vendor "Schneider-electric" for product "Smt Series 18 Ups Firmware"
<= 09.8
Search vendor "Schneider-electric" for product "Smt Series 18 Ups Firmware" and version " <= 09.8"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smt Series 18 Ups
Search vendor "Schneider-electric" for product "Smt Series 18 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Smt Series 1040 Ups Firmware
Search vendor "Schneider-electric" for product "Smt Series 1040 Ups Firmware"
<= 01.2
Search vendor "Schneider-electric" for product "Smt Series 1040 Ups Firmware" and version " <= 01.2"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smt Series 1040 Ups
Search vendor "Schneider-electric" for product "Smt Series 1040 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Smt Series 1031 Ups Firmware
Search vendor "Schneider-electric" for product "Smt Series 1031 Ups Firmware"
<= 03.1
Search vendor "Schneider-electric" for product "Smt Series 1031 Ups Firmware" and version " <= 03.1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smt Series 1031 Ups
Search vendor "Schneider-electric" for product "Smt Series 1031 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Smc Series 1005 Ups Firmware
Search vendor "Schneider-electric" for product "Smc Series 1005 Ups Firmware"
<= 14.1
Search vendor "Schneider-electric" for product "Smc Series 1005 Ups Firmware" and version " <= 14.1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smc Series 1005 Ups
Search vendor "Schneider-electric" for product "Smc Series 1005 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Smc Series 1007 Ups Firmware
Search vendor "Schneider-electric" for product "Smc Series 1007 Ups Firmware"
<= 11.0
Search vendor "Schneider-electric" for product "Smc Series 1007 Ups Firmware" and version " <= 11.0"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smc Series 1007 Ups
Search vendor "Schneider-electric" for product "Smc Series 1007 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Smc Series 1041 Ups Firmware
Search vendor "Schneider-electric" for product "Smc Series 1041 Ups Firmware"
<= 01.1
Search vendor "Schneider-electric" for product "Smc Series 1041 Ups Firmware" and version " <= 01.1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smc Series 1041 Ups
Search vendor "Schneider-electric" for product "Smc Series 1041 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1030 Ups Firmware
Search vendor "Schneider-electric" for product "Scl Series 1030 Ups Firmware"
<= 02.5
Search vendor "Schneider-electric" for product "Scl Series 1030 Ups Firmware" and version " <= 02.5"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1030 Ups
Search vendor "Schneider-electric" for product "Scl Series 1030 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1036 Ups Firmware
Search vendor "Schneider-electric" for product "Scl Series 1036 Ups Firmware"
<= 02.5
Search vendor "Schneider-electric" for product "Scl Series 1036 Ups Firmware" and version " <= 02.5"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Scl Series 1036 Ups
Search vendor "Schneider-electric" for product "Scl Series 1036 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Smx Series 20 Ups Firmware
Search vendor "Schneider-electric" for product "Smx Series 20 Ups Firmware"
<= 10.2
Search vendor "Schneider-electric" for product "Smx Series 20 Ups Firmware" and version " <= 10.2"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smx Series 20 Ups
Search vendor "Schneider-electric" for product "Smx Series 20 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Smx Series 23 Ups Firmware
Search vendor "Schneider-electric" for product "Smx Series 23 Ups Firmware"
<= 07.0
Search vendor "Schneider-electric" for product "Smx Series 23 Ups Firmware" and version " <= 07.0"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Smx Series 23 Ups
Search vendor "Schneider-electric" for product "Smx Series 23 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1010 Ups Firmware
Search vendor "Schneider-electric" for product "Srt Series 1010 Ups Firmware"
<= 08.3
Search vendor "Schneider-electric" for product "Srt Series 1010 Ups Firmware" and version " <= 08.3"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1010 Ups
Search vendor "Schneider-electric" for product "Srt Series 1010 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1019 Ups Firmware
Search vendor "Schneider-electric" for product "Srt Series 1019 Ups Firmware"
<= 08.3
Search vendor "Schneider-electric" for product "Srt Series 1019 Ups Firmware" and version " <= 08.3"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1019 Ups
Search vendor "Schneider-electric" for product "Srt Series 1019 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1025 Ups Firmware
Search vendor "Schneider-electric" for product "Srt Series 1025 Ups Firmware"
<= 08.3
Search vendor "Schneider-electric" for product "Srt Series 1025 Ups Firmware" and version " <= 08.3"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1025 Ups
Search vendor "Schneider-electric" for product "Srt Series 1025 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1020 Ups Firmware
Search vendor "Schneider-electric" for product "Srt Series 1020 Ups Firmware"
<= 10.4
Search vendor "Schneider-electric" for product "Srt Series 1020 Ups Firmware" and version " <= 10.4"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1020 Ups
Search vendor "Schneider-electric" for product "Srt Series 1020 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1021 Ups Firmware
Search vendor "Schneider-electric" for product "Srt Series 1021 Ups Firmware"
<= 12.2
Search vendor "Schneider-electric" for product "Srt Series 1021 Ups Firmware" and version " <= 12.2"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1021 Ups
Search vendor "Schneider-electric" for product "Srt Series 1021 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1001 Ups Firmware
Search vendor "Schneider-electric" for product "Srt Series 1001 Ups Firmware"
<= 05.1
Search vendor "Schneider-electric" for product "Srt Series 1001 Ups Firmware" and version " <= 05.1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1001 Ups
Search vendor "Schneider-electric" for product "Srt Series 1001 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1013 Ups Firmware
Search vendor "Schneider-electric" for product "Srt Series 1013 Ups Firmware"
<= 05.1
Search vendor "Schneider-electric" for product "Srt Series 1013 Ups Firmware" and version " <= 05.1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1013 Ups
Search vendor "Schneider-electric" for product "Srt Series 1013 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1002 Ups Firmware
Search vendor "Schneider-electric" for product "Srt Series 1002 Ups Firmware"
<= a05.2
Search vendor "Schneider-electric" for product "Srt Series 1002 Ups Firmware" and version " <= a05.2"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1002 Ups
Search vendor "Schneider-electric" for product "Srt Series 1002 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1014 Ups Firmware
Search vendor "Schneider-electric" for product "Srt Series 1014 Ups Firmware"
<= a05.2
Search vendor "Schneider-electric" for product "Srt Series 1014 Ups Firmware" and version " <= a05.2"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srt Series 1014 Ups
Search vendor "Schneider-electric" for product "Srt Series 1014 Ups"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srtl1000rmxli Firmware
Search vendor "Schneider-electric" for product "Srtl1000rmxli Firmware"
<= 01.0
Search vendor "Schneider-electric" for product "Srtl1000rmxli Firmware" and version " <= 01.0"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srtl1000rmxli
Search vendor "Schneider-electric" for product "Srtl1000rmxli"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srtl1000rmxli-nc Firmware
Search vendor "Schneider-electric" for product "Srtl1000rmxli-nc Firmware"
<= 01.0
Search vendor "Schneider-electric" for product "Srtl1000rmxli-nc Firmware" and version " <= 01.0"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srtl1000rmxli-nc
Search vendor "Schneider-electric" for product "Srtl1000rmxli-nc"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srtl1500rmxli-nc Firmware
Search vendor "Schneider-electric" for product "Srtl1500rmxli-nc Firmware"
<= 01.0
Search vendor "Schneider-electric" for product "Srtl1500rmxli-nc Firmware" and version " <= 01.0"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srtl1500rmxli-nc
Search vendor "Schneider-electric" for product "Srtl1500rmxli-nc"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srtl1500rmxli Firmware
Search vendor "Schneider-electric" for product "Srtl1500rmxli Firmware"
<= 01.0
Search vendor "Schneider-electric" for product "Srtl1500rmxli Firmware" and version " <= 01.0"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srtl1500rmxli
Search vendor "Schneider-electric" for product "Srtl1500rmxli"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srtl2200rmxli Firmware
Search vendor "Schneider-electric" for product "Srtl2200rmxli Firmware"
<= 01.0
Search vendor "Schneider-electric" for product "Srtl2200rmxli Firmware" and version " <= 01.0"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srtl2200rmxli
Search vendor "Schneider-electric" for product "Srtl2200rmxli"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srtl2200rmxli-nc Firmware
Search vendor "Schneider-electric" for product "Srtl2200rmxli-nc Firmware"
<= 01.0
Search vendor "Schneider-electric" for product "Srtl2200rmxli-nc Firmware" and version " <= 01.0"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srtl2200rmxli-nc
Search vendor "Schneider-electric" for product "Srtl2200rmxli-nc"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srtl3000rmxli-nc Firmware
Search vendor "Schneider-electric" for product "Srtl3000rmxli-nc Firmware"
<= 01.0
Search vendor "Schneider-electric" for product "Srtl3000rmxli-nc Firmware" and version " <= 01.0"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srtl3000rmxli-nc
Search vendor "Schneider-electric" for product "Srtl3000rmxli-nc"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Srtl3000rmxli Firmware
Search vendor "Schneider-electric" for product "Srtl3000rmxli Firmware"
<= 01.0
Search vendor "Schneider-electric" for product "Srtl3000rmxli Firmware" and version " <= 01.0"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Srtl3000rmxli
Search vendor "Schneider-electric" for product "Srtl3000rmxli"
--
Safe