PT-2018-13156 · Advantech · Advantech Webaccess

Lynerc

·

Publicado

2018-10-31

·

Atualizado

2018-12-12

·

CVE-2018-15705

CVSS v2.0

8.5

Alta

VetorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Advantech WebAccess versions 8.3.1 through 8.3.2
Description The issue allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API endpoint. This can be used to remotely execute arbitrary code.
Recommendations For Advantech WebAccess versions 8.3.1 and 8.3.2, consider restricting access to the writeFile API endpoint until a patch is available. As a temporary workaround, limit the ability to write or overwrite files on the filesystem to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-15705

Produtos afetados

Advantech Webaccess