A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMicrosoft Windows 10
OSMicrosoftall versionsMicrosoft Windows 11
OSMicrosoftall versionsMicrosoft Windows Server 2016
OSMicrosoftall versionsMicrosoft Windows Server 2019
OSMicrosoftall versionsMicrosoft Windows Server 2022
OSMicrosoftall versionsSchneider Electric Apc Easy Ups Online Monitoring Software
APPSchneider-Electric≤ 2.5-ga-01-22320Schneider Electric Easy Ups Online Monitoring Software
APPSchneider-Electric≤ 2.5-gs-01-22320
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product
Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu
CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product
RCE w Windows Server Update Service (WSUS) — deserializacja danych
CVE-2020-1350CRITICAL10.0⚠ KEVPL ✓same product
RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)
CVE-2020-1040CRITICAL9.0⚠ KEVPL ✓same product
RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa
CVE-2020-0646CRITICAL9.8⚠ KEVPL ✓same product
RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych