PT-2019-16794 · Advantech · Webaccess

Publicado

2019-04-09

·

Atualizado

2019-10-09

·

CVE-2019-3940

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech WebAccess version 8.3.4
Description The issue allows an unauthenticated, remote attacker to execute arbitrary code via file upload attacks using an unauthenticated RPC call.
Recommendations For Advantech WebAccess version 8.3.4, consider restricting access to the RPC call to prevent unauthenticated file uploads until a patch is available.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-3940

Produtos afetados

Webaccess