vendor:
PowerChute Plus
by:
SecurityFocus
7.5
CVSS
HIGH
Remote Denial of Service
399
CWE
Product Name: PowerChute Plus
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Solaris i386
2002
APC PowerChute Plus Remote Denial of Service Vulnerability
A request packet can be crafted and sent to the UDP port such that the upsd server will crash. This has been tested in the Solaris i386 version of the product. It has also been reported the software will crash in some instances when port scanned. It seems you can also manage any APC UPS remotely without providing any credential if you have the APC client software. Both the client and server software also create files insecurely in /tmp. The pager script (dialpager.sh) also contains unsafe users of temporary files. The mailer script (mailer.sh) passes the files provided in the command line to rm without checking them.
Mitigation:
Ensure that the APC PowerChute Plus software is up to date and that all security patches are applied.