← العودة للجدول
CVE-2022-42971
CVE-2022-42971 — A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists
📅 2023-02-01
🔴 Critical 🔥 No NVD Exploit Microsoft CVSS 9.8 🎯 EPSS 2.58%

📋 الوصف الكامل

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versio

💻 الأنظمة المتأثرة

Windows 11 | Windows Server 2019 | Windows Server

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2022-42971

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2.5

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←