This vulnerability allows local malicious users to create a denial-of-service condition on affected installations of Schneider Electric APC Easy UPS Online. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the deletePdfReportFile method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
schneider-electric easy_ups_online_monitoring_software |