apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf("%*s %*s %s", answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf("%*s %*s %s", answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response. | |
| First Time appeared |
Apcupsd
Apcupsd apcupsd |
|
| Weaknesses | CWE-457 | |
| CPEs | cpe:2.3:a:apcupsd:apcupsd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apcupsd
Apcupsd apcupsd |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-30T15:38:48.231Z
Reserved: 2026-09-30T15:38:47.884Z
Link: CVE-2026-103436
No data.
Status : Deferred
Published: 2026-09-30T16:17:09.700
Modified: 2026-09-30T17:32:07.107
Link: CVE-2026-103436
No data.
OpenCVE Enrichment
No data.
Weaknesses