PT-2016-1121 · Advantech · Webaccess

Aleksey Osipov

+1

·

Published

2016-01-15

·

Updated

2016-12-03

·

CVE-2016-0854

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech WebAccess versions prior to 8.1
Description The issue is related to an unrestricted file upload vulnerability. This vulnerability can be exploited by a remote attacker to modify files of any type. The vulnerability is associated with the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer.
Recommendations For versions prior to 8.1, update to version 8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the uploadImageCommon function in the UploadAjaxAction script until a patch is available. Restrict access to the UploadAjaxAction script to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00380
CVE-2016-0854
ZDI-16-127
ZDI-16-128
ZDI-16-129

Affected Products

Webaccess