Advantech WebAccess ICSA-17-241-02 Multiple Security Vulnerabilities
BID:100526
CVE-2017-12698 | CVE-2017-12702 | CVE-2017-12704 | CVE-2017-12706 | CVE-2017-12708 | CVE-2017-12710 | CVE-2017-12711 | CVE-2017-12713 | CVE-2017-12717 |Info
Advantech WebAccess ICSA-17-241-02 Multiple Security Vulnerabilities
| Bugtraq ID: | 100526 |
| Class: | Unknown |
| CVE: |
CVE-2017-12702 CVE-2017-12704 CVE-2017-12706 CVE-2017-12708 CVE-2017-12710 CVE-2017-12698 CVE-2017-12717 CVE-2017-12711 CVE-2017-12713 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 29 2017 12:00AM |
| Updated: | Aug 29 2017 12:00AM |
| Credit: | Fritz Sands, rgod, Tenable Network Security,an anonymous researcher all working with Trend Micro�??s Zero Day Initiative, and Haojun Hou and DongWang from ADLab of Venustech. |
| Vulnerable: |
Advantech WebAccess 8.2_20170330 Advantech WebAccess 8.2 Advantech WebAccess 8.1_20160519 Advantech WebAccess 8.0_20150816 Advantech WebAccess 8 |
| Not Vulnerable: |
Advantech WebAccess 8.2_20170817 Advantech WebAccess 8.1 |
Discussion
Advantech WebAccess ICSA-17-241-02 Multiple Security Vulnerabilities
Advantech WebAccess is prone to the following security vulnerabilities:
1. Multiple stack-based buffer-overflow vulnerabilities
2. Multiple heap-based buffer-overflow vulnerabilities.
3. Multiple memory-corruption vulnerabilities.
4. An SQL-injection vulnerability.
5. A format-string vulnerability.
6. An authentication-bypass vulnerability.
7. A security-bypass vulnerability.
8. A privilege-escalation vulnerability.
9. A remote-code execution vulnerability.
An attacker can exploit these issues to execute arbitrary code in the context of the application, or modify data, or exploit latent vulnerabilities in the underlying database,perform certain unauthorized actions, gain unauthorized access and gain elevated privileges. This may aid in further attacks.
Advantech WebAccess versions prior to V8.2_20170817 are vulnerable.
Advantech WebAccess is prone to the following security vulnerabilities:
1. Multiple stack-based buffer-overflow vulnerabilities
2. Multiple heap-based buffer-overflow vulnerabilities.
3. Multiple memory-corruption vulnerabilities.
4. An SQL-injection vulnerability.
5. A format-string vulnerability.
6. An authentication-bypass vulnerability.
7. A security-bypass vulnerability.
8. A privilege-escalation vulnerability.
9. A remote-code execution vulnerability.
An attacker can exploit these issues to execute arbitrary code in the context of the application, or modify data, or exploit latent vulnerabilities in the underlying database,perform certain unauthorized actions, gain unauthorized access and gain elevated privileges. This may aid in further attacks.
Advantech WebAccess versions prior to V8.2_20170817 are vulnerable.
Exploit / POC
Advantech WebAccess ICSA-17-241-02 Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Advantech WebAccess ICSA-17-241-02 Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Advantech WebAccess ICSA-17-241-02 Multiple Security Vulnerabilities
References:
References:
- Advantech WebAccess Homepage (Advantech)
- ICSA-17-241-02:Advantech WebAccess (CERT)