Advantech WebAccess ICSA-18-004-02 Multiple Security Vulnerabilities
BID:102424
CVE-2017-16716 | CVE-2017-16720 | CVE-2017-16724 | CVE-2017-16728 | CVE-2017-16753 |Info
Advantech WebAccess ICSA-18-004-02 Multiple Security Vulnerabilities
| Bugtraq ID: | 102424 |
| Class: | Unknown |
| CVE: |
CVE-2017-16728 CVE-2017-16724 CVE-2017-16720 CVE-2017-16716 CVE-2017-16753 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 04 2018 12:00AM |
| Updated: | Jan 04 2018 12:00AM |
| Credit: | Steven Seeley of Offensive Security, Zhou Yu and Andrea Micalizzi working with Trend Micro�??s Zero Day Initiative, and Michael Deplante. |
| Vulnerable: |
Advantech WebAccess 8.2_20170330 Advantech WebAccess 8.2 Advantech WebAccess 8.1_20160519 Advantech WebAccess 8.1 Advantech WebAccess 8.0_20150816 Advantech WebAccess 8 Advantech WebAccess 7.2 |
| Not Vulnerable: |
Advantech WebAccess 8.3 |
Discussion
Advantech WebAccess ICSA-18-004-02 Multiple Security Vulnerabilities
Advantech WebAccess is prone to the following security vulnerabilities:
1. Multiple denial-of-service vulnerabilities
2. Multiple stack-based buffer-overflow vulnerabilities
3. A directory-traversal vulnerability
4. An SQL-injection vulnerability
5. Multiple denial-of-service vulnerabilities
An attacker can exploit these issues to execute arbitrary code in the context of the application, or modify data, or exploit latent vulnerabilities in the underlying database,perform certain unauthorized actions, gain unauthorized access and obtain sensitive information. Failed attacks will cause denial of service conditions.
versions prior to Advantech WebAccess 8.3 are vulnerable.
Advantech WebAccess is prone to the following security vulnerabilities:
1. Multiple denial-of-service vulnerabilities
2. Multiple stack-based buffer-overflow vulnerabilities
3. A directory-traversal vulnerability
4. An SQL-injection vulnerability
5. Multiple denial-of-service vulnerabilities
An attacker can exploit these issues to execute arbitrary code in the context of the application, or modify data, or exploit latent vulnerabilities in the underlying database,perform certain unauthorized actions, gain unauthorized access and obtain sensitive information. Failed attacks will cause denial of service conditions.
versions prior to Advantech WebAccess 8.3 are vulnerable.
Exploit / POC
Advantech WebAccess ICSA-18-004-02 Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Advantech WebAccess ICSA-18-004-02 Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Advantech WebAccess ICSA-18-004-02 Multiple Security Vulnerabilities
References:
References:
- Advantech WebAccess Homepage (Advantech)
- ICSA-18-004-02: Advantech WebAccess (CERT)