CVE-2023-29411: Schneider Electric Apc Easy Ups Online Monitoring Software

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.

Affected products

  • Schneider Electric Apc Easy Ups Online Monitoring Software: up to and including 2.5-ga-01-22320
  • Schneider Electric Easy Ups Online Monitoring Software: up to and including 2.5-gs-01-22320

Published 2023-04-18. Last modified 2026-06-17.