PT-2020-12249 · Advantech · Webaccess/Nms

Published

2020-04-08

·

Updated

2020-04-10

·

CVE-2020-10621

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Advantech WebAccess/NMS versions prior to 3.0.2
Description The issue allows files to be uploaded and executed on the WebAccess/NMS, potentially leading to remote code execution. This is due to multiple unrestricted file upload vulnerabilities in various actions and resources, including extProgramAction, ProfileResource, DBBackupRestoreAction, LicenseImportAction, DBBackupResource, saveBackground, ConfigRestoreAction, SupportDeviceaddAction, and FwUpgradeAction.
Recommendations For versions prior to 3.0.2, update to version 3.0.2 or later to resolve the issue. As a temporary workaround, consider disabling the vulnerable actions and resources until a patch is available. Restrict access to the WebAccess/NMS to minimize the risk of exploitation. Avoid using the affected actions and resources in the WebAccess/NMS until the issue is resolved.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10621
ZDI-20-373
ZDI-20-383
ZDI-20-385
ZDI-20-386
ZDI-20-387
ZDI-20-389
ZDI-20-397
ZDI-20-400
ZDI-20-402
ZDI-20-405
ZDI-20-406

Affected Products

Webaccess/Nms