Improper access control in Smart-UPS SRT 5000 - #VU58283
Published: November 22, 2021
Smart-UPS SRT 5000
Schneider Electric
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to a misconfiguration on user creation implementation issue. A remote attacker can create a hidden user account that could be served as a backdoor account not visible from the user management interface.