Apcupsd is a widely deployed open-source daemon for monitoring and managing APC uninterruptible power supplies, typically embedded in server and data-center infrastructure where it handles privileged device communication and web-based status interfaces. Its observed vulnerability patterns center on input-handling and command-execution issues, including cross-site scripting, OS command injection, and uncontrolled search path elements, reflecting the complexity of parsing user-supplied data and invoking system commands in a daemon with direct hardware access. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apcupsd over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12585CRITICAL Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php. | Jun 3, 2019 | 9.8 | 31 | NO | NO |
CVE-2003-0098HIGH Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server | Mar 3, 2003 | 10.0 | 30 | NO | NO |
CVE-2017-7884HIGH In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevate | Jun 16, 2017 | 8.4 | 24 | NO | NO |
CVE-2019-12584MEDIUM Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php. | Jun 3, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apcupsd.
Media articles that mention a CVE ID that affects a product developed by Apcupsd — matched by CVE ID, not by vendor name.