PT-2018-13156 · Advantech · Advantech Webaccess

Lynerc

·

Published

2018-10-31

·

Updated

2018-12-12

·

CVE-2018-15705

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Advantech WebAccess versions 8.3.1 through 8.3.2
Description The issue allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API endpoint. This can be used to remotely execute arbitrary code.
Recommendations For Advantech WebAccess versions 8.3.1 and 8.3.2, consider restricting access to the writeFile API endpoint until a patch is available. As a temporary workaround, limit the ability to write or overwrite files on the filesystem to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15705

Affected Products

Advantech Webaccess