PT-2020-12981 · Advantech · Advantech Webaccess Node

Published

2020-04-08

·

Updated

2021-09-23

·

CVE-2020-12010

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech WebAccess Node versions 8.4.4 and prior Advantech WebAccess Node version 9.0.0
Description Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control. The issue involves the use of IOCTL commands, including 0x2711, 0x2715, and 0x2738, which can lead to arbitrary file deletion vulnerabilities in various components such as BwFLApp, BwPFile, and BwPSLink.
Recommendations For Advantech WebAccess Node versions 8.4.4 and prior, consider restricting access to the application until a patch is available. For Advantech WebAccess Node version 9.0.0, consider disabling the use of IOCTL commands 0x2711, 0x2715, and 0x2738 as a temporary workaround until a patch is available. As a general mitigation measure, restrict access to the vulnerable components, such as BwFLApp, BwPFile, and BwPSLink, to minimize the risk of exploitation.

Fix

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12010
ZDI-20-446
ZDI-20-447
ZDI-20-448
ZDI-20-449
ZDI-20-450

Affected Products

Advantech Webaccess Node