PT-2018-13156 · Advantech · Advantech Webaccess
Lynerc
·
Publicado
2018-10-31
·
Atualizado
2018-12-12
·
CVE-2018-15705
CVSS v2.0
8.5
Alta
| Vetor | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Advantech WebAccess versions 8.3.1 through 8.3.2
Description
The issue allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the
writeFile API endpoint. This can be used to remotely execute arbitrary code.Recommendations
For Advantech WebAccess versions 8.3.1 and 8.3.2, consider restricting access to the
writeFile API endpoint until a patch is available. As a temporary workaround, limit the ability to write or overwrite files on the filesystem to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Advantech Webaccess