Powerchute
Vendor:
First CVE: Dec 31, 2000 · Active for 25 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Powerchute over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2000
25 years ago
Most Recent CVE
Aug 31, 2020
2,155 days ago
CVE Severity & Scoring
Powerchute5 CVEs
60%
40%
All CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (20.0%)
Unknown4 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (20.0%)
High0 (0.0%)
Unknown4 (80.0%)
User Interaction
None1 (20.0%)
Unknown4 (80.0%)
Required0 (0.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None0 (0.0%)
Unknown4 (80.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7526HIGH Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code execution when a script is executed during | Aug 31, 2020 | 8.8 | 26 | NO | NO |
CVE-2000-1242HIGH The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access. | Dec 31, 2000 | 9.0 | 22 | NO | NO |
CVE-2011-4263MEDIUM Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbitrary web script or HTML via unspecified | Dec 7, 2011 | 4.3 | 16 | NO | NO |
CVE-2004-2046MEDIUM Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown attack vectors. | Dec 31, 2004 | 5.0 | 15 | NO | NO |
CVE-2002-1924MEDIUM PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attackers to modify or create files in that di | Dec 31, 2002 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Powerchute
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.1 | 2 | 4.7 | 1.7% | 0 | 0 |
| 7.0.4 | 1 | 4.3 | 0.9% | 0 | 0 |
| 6.0 | 2 | 4.7 | 1.7% | 0 | 0 |
| 5.0.2 | 1 | 5.0 | 1.4% | 0 | 0 |