GPU VulnDB

Database/Firmware, BMC & network fabric

APC Easy UPS On-Line Software (SFAPV9601) FileUploadServlet: Path traversal in a file upload servlet allows writing

CVE-2020-7521Firmware, BMC & network fabricSEVD-2020-224-01curated

Impact

Path traversal in a file upload servlet allows writing an executable anywhere on the host, giving code execution on the machine that manages UPS shutdown across the site. Same PHYSICAL end state as the newer Easy UPS bugs - an attacker gains the ability to command an orderly power-down of everything the software manages.

Who can reach it

Unauthenticated network access to the software's web servlet.

What to do

Upgrade past v2.0. Server-side upgrade, cheap. If the host was exposed, rebuild rather than patch - and rotate every UPS and host credential it stored.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.