PT-2018-13156 · Advantech · Advantech Webaccess
Lynerc
·
Published
2018-10-31
·
Updated
2018-12-12
·
CVE-2018-15705
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Advantech WebAccess versions 8.3.1 through 8.3.2
Description
The issue allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the
writeFile API endpoint. This can be used to remotely execute arbitrary code.Recommendations
For Advantech WebAccess versions 8.3.1 and 8.3.2, consider restricting access to the
writeFile API endpoint until a patch is available. As a temporary workaround, limit the ability to write or overwrite files on the filesystem to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advantech Webaccess