"value":"\nA CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow\nchanges to administrative credentials, leading to potential remote code execution without\nrequiring prior authentication on the Java RMI interface. \n\n\n\n"
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-306 Missing Authentication for Critical Function",
"cweId":"CWE-306"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Schneider Electric",
"product":{
"product_data":[
{
"product_name":"APC Easy UPS Online Monitoring Software (Windows 10, 11 Windows Server 2016, 2019, 2022)",
"version":{
"version_data":[
{
"version_affected":"<=",
"version_name":"V2.5-GA-01-22320",
"version_value":"prior"
}
]
}
},
{
"product_name":"Schneider Electric Easy UPS Online Monitoring Software (Windows 10, 11 Windows Server 2016, 2019, 2022)",