GPU VulnDB

Database/Firmware, BMC & network fabric

APC Easy UPS Online Monitoring Software - embedded database credentials: Hardcoded credentials let any local user

CVE-2022-42973Firmware, BMC & network fabricSEVD-2022-256-01curated

Impact

Hardcoded credentials let any local user connect to the software's database and escalate. The database holds the site's UPS inventory and the credentials used to command shutdowns, so this converts a low-privilege foothold on one Windows host into control of the power-shutdown path.

Who can reach it

Local access to the machine running the monitoring software.

What to do

Software upgrade. Hardcoded credentials mean the value is public once the advisory ships, so also confirm the database is not listening beyond localhost. Cheap to fix, and worth doing in the same window as the two RCEs above.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.