PT-2020-12249 · Advantech · Webaccess/Nms
Published
2020-04-08
·
Updated
2020-04-10
·
CVE-2020-10621
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Advantech WebAccess/NMS versions prior to 3.0.2
Description
The issue allows files to be uploaded and executed on the WebAccess/NMS, potentially leading to remote code execution. This is due to multiple unrestricted file upload vulnerabilities in various actions and resources, including
extProgramAction, ProfileResource, DBBackupRestoreAction, LicenseImportAction, DBBackupResource, saveBackground, ConfigRestoreAction, SupportDeviceaddAction, and FwUpgradeAction.Recommendations
For versions prior to 3.0.2, update to version 3.0.2 or later to resolve the issue.
As a temporary workaround, consider disabling the vulnerable actions and resources until a patch is available.
Restrict access to the WebAccess/NMS to minimize the risk of exploitation.
Avoid using the affected actions and resources in the WebAccess/NMS until the issue is resolved.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webaccess/Nms