vendor:
Symmetra Uninterruptable Power Supply
by:
altomo
4.3
CVSS
MEDIUM
Denial of Service
N/A
CWE
Product Name: Symmetra Uninterruptable Power Supply
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
APC Management Card Denial of Service
A problem with the network software used with the Symmetra Uninterruptable Power Supply manufactured by American Power Conversation Corporation (APC) can allow a denial of service to the system, thus preventing administrative access. This problem is due to the handling of the telnet protocol by the firmware of the power supply. The system does not support more than one telnet session at a time, and when it encounters three failed login attempts, discontinues access for a configurable period between 1 and 10 minutes.
Mitigation:
Limit the number of failed login attempts and configure the system to disconnect after a certain number of failed attempts.