PT-2020-12251 · Advantech · Advantech Webaccess/Nms

Rgod

·

Published

2020-04-08

·

Updated

2020-04-10

·

CVE-2020-10623

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Advantech WebAccess/NMS versions prior to 3.0.2
Description The issue allows an attacker with low privileges to perform SQL injection on Advantech WebAccess/NMS, potentially gaining access to sensitive information. This is made possible through vulnerabilities such as SQL injection in the getFWUpgradeInfo, getSyslogUiList, and setDevicechoose functions.
Recommendations For Advantech WebAccess/NMS versions prior to 3.0.2, update to version 3.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the getFWUpgradeInfo, getSyslogUiList, and setDevicechoose functions until a patch is available.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10623
ZDI-20-413
ZDI-20-420
ZDI-20-421

Affected Products

Advantech Webaccess/Nms