PT-2016-4422 · Advantech · Advantech Webaccess

Kimiya

+1

·

Published

2016-01-15

·

Updated

2016-12-03

·

CVE-2016-0855

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Advantech WebAccess versions prior to 8.1
Description The issue allows remote attackers to list arbitrary virtual-directory files via unspecified vectors. It also enables directory traversal, which can lead to arbitrary file deletion, denial of service, and information disclosure. The vulnerability is related to the Dashboard Viewer and affects various functions such as addFolder, removeFolder, openWidget, and removeFile.
Recommendations For Advantech WebAccess versions prior to 8.1, update to version 8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Dashboard Viewer functions, specifically addFolder, removeFolder, openWidget, and removeFile, until a patch is available.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-0855
ZDI-16-122
ZDI-16-123
ZDI-16-124
ZDI-16-125
ZDI-16-126

Affected Products

Advantech Webaccess