PT-2016-4422 · Advantech · Advantech Webaccess

Kimiya

+1

·

Publicado

2016-01-15

·

Atualizado

2016-12-03

·

CVE-2016-0855

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Advantech WebAccess versions prior to 8.1
Description The issue allows remote attackers to list arbitrary virtual-directory files via unspecified vectors. It also enables directory traversal, which can lead to arbitrary file deletion, denial of service, and information disclosure. The vulnerability is related to the Dashboard Viewer and affects various functions such as addFolder, removeFolder, openWidget, and removeFile.
Recommendations For Advantech WebAccess versions prior to 8.1, update to version 8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Dashboard Viewer functions, specifically addFolder, removeFolder, openWidget, and removeFile, until a patch is available.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-0855
ZDI-16-122
ZDI-16-123
ZDI-16-124
ZDI-16-125
ZDI-16-126

Produtos afetados

Advantech Webaccess