PowerChute PLUS Denial of Service...

- AV AC AU C I A
发布: 1998-04-10
修订: 2025-04-13

APC PowerChute PLUS is a software package that will safely shutdown computer systems locally or accross a network when UPS power starts to fail. When operating PowerChute PLUS normally listens to TCP ports 6547 and 6548, as well as for broadcast requests in UDP port 6549. A request packet can be craftted and sent to the UDP port such that the upsd server will crash. This is been tested in the Solaris i386 version of the product. It has also been reported the software will crash in some instances when port scanned. It seems you can also manage any APC UPS remotely without providing any credential if you have the APC client software. Both the client and server software also create files insecurely in /tmp. The pager script (dialpager.sh) also contains unsafe users of temporary files. The mailer script (mailer.sh) passes the files provided in the command line to rm without checking them.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息