{"api_version":"1","generated_at":"2026-07-23T12:01:01+00:00","cve":"CVE-2017-7929","urls":{"html":"https://cve.report/CVE-2017-7929","api":"https://cve.report/api/cve/CVE-2017-7929.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-7929","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-7929"},"summary":{"title":"CVE-2017-7929","description":"An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to access restricted files or directories.","state":"PUBLISHED","assigner":"icscert","published_at":"2017-05-06 00:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-36","CWE-22","CWE-36 CWE-36"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.1","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:P","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/98311","name":"http://www.securityfocus.com/bid/98311","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-124-03","name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-124-03","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Third Party Advisory","US Government Resource"],"title":"Advantech WebAccess | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-7929","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7929","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Advantech WebAccess","version":"affected Advantech WebAccess","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"7929","vulnerable":"1","versionEndIncluding":"8.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"advantech","cpe5":"webaccess","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T16:19:29.504Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"98311","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/98311"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-124-03"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Advantech WebAccess","vendor":"n/a","versions":[{"status":"affected","version":"Advantech WebAccess"}]}],"datePublic":"2017-05-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to access restricted files or directories."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-36","description":"CWE-36","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-05-08T09:57:01.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"name":"98311","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/98311"},{"tags":["x_refsource_MISC"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-124-03"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-7929","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Advantech WebAccess","version":{"version_data":[{"version_value":"Advantech WebAccess"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to access restricted files or directories."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-36"}]}]},"references":{"reference_data":[{"name":"98311","refsource":"BID","url":"http://www.securityfocus.com/bid/98311"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-124-03","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-124-03"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2017-7929","datePublished":"2017-05-06T00:00:00.000Z","dateReserved":"2017-04-18T00:00:00.000Z","dateUpdated":"2024-08-05T16:19:29.504Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-05-06 00:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-36","CWE-22","CWE-36 CWE-36"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:P","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:advantech:webaccess:*:*:*:*:*:*:*:*","versionEndIncluding":"8.1","matchCriteriaId":"715345BC-B19A-4605-AB4E-C26AB4F4D65C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"7929","Ordinal":"1","Title":"CVE-2017-7929","CVE":"CVE-2017-7929","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"7929","Ordinal":"1","NoteData":"An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to access restricted files or directories.","Type":"Description","Title":"CVE-2017-7929"},{"CveYear":"2017","CveId":"7929","Ordinal":"2","NoteData":"2017-05-05","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"7929","Ordinal":"3","NoteData":"2017-05-08","Type":"Other","Title":"Modified"}]}}}