PT-2019-13420 · Advantech · Webaccess

Publicado

2019-09-18

·

Atualizado

2019-10-09

·

CVE-2019-13558

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WebAccess versions 8.4.1 and prior
Description The issue allows for improper control of code generation, potentially enabling remote code execution, data exfiltration, or causing a system crash when an exploit is executed over the network.
Recommendations For versions 8.4.1 and prior, update to a version later than 8.4.1 to resolve the issue.

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-13558

Produtos afetados

Webaccess