VulnerabilityModified
CVE-2004-0311
American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.
HIGH 10.0EPSS 2.47%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.47% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- apc/ap9606
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=107703696631367&w=2
- http://marc.info/?l=bugtraq&m=107721020803565&w=2
- http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=3131&p_created=1077139129
- http://www.securityfocus.com/bid/9681Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15238
- http://marc.info/?l=bugtraq&m=107703696631367&w=2
- http://marc.info/?l=bugtraq&m=107721020803565&w=2
- http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=3131&p_created=1077139129
- http://www.securityfocus.com/bid/9681Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15238
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.