SCADA: Schneider Electric APC Easy UPS Online getMacAddressByIP Command Injection

This signature detects attempts to exploit a known vulnerability against Schneider Electric APC Easy UPS Online getMacAddressByIP. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.

Short Name
SCADA:SCHNEIDER-APC-UPS-CI
Severity
Major
Recommended
False
Recommended Action
None
Category
SCADA
Keywords
APC CVE-2023-29412 Command Easy Electric Injection Online Schneider UPS getMacAddressByIP
Release Date
05/19/2023
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3713
False Positive
Rarely

Found a potential security threat?