CRITICAL🇵🇱 Wersja polska

CVE-2023-29411

CVSS 9.8v3.1pub. 2023-04-18upd. 2024-11-21

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Microsoft Windows 10

    OS
    Microsoft
    all versions
  • Microsoft Windows 11

    OS
    Microsoft
    all versions
  • Microsoft Windows Server 2016

    OS
    Microsoft
    all versions
  • Microsoft Windows Server 2019

    OS
    Microsoft
    all versions
  • Microsoft Windows Server 2022

    OS
    Microsoft
    all versions
  • Schneider Electric Apc Easy Ups Online Monitoring Software

    APP
    Schneider-Electric
    ≤ 2.5-ga-01-22320
  • Schneider Electric Easy Ups Online Monitoring Software

    APP
    Schneider-Electric
    ≤ 2.5-gs-01-22320
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product

Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu

CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product

RCE w Windows Server Update Service (WSUS) — deserializacja danych

CVE-2020-1350CRITICAL10.0⚠ KEVPL ✓same product

RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)

CVE-2020-1040CRITICAL9.0⚠ KEVPL ✓same product

RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa

CVE-2020-0646CRITICAL9.8⚠ KEVPL ✓same product

RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych