Advantech ICSA-18-296-01 WebAccess Multiple Security Vulnerabilities
BID:105728
CVE-2018-14806 | CVE-2018-14816 | CVE-2018-14820 | CVE-2018-14828 |Info
Advantech ICSA-18-296-01 WebAccess Multiple Security Vulnerabilities
| Bugtraq ID: | 105728 |
| Class: | Design Error |
| CVE: |
CVE-2018-14816 CVE-2018-14806 CVE-2018-14820 CVE-2018-14828 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2018 12:00AM |
| Updated: | Oct 23 2018 12:00AM |
| Credit: | Mat Powell of Trend Micro Zero Day Initiative |
| Vulnerable: |
Advantech WebAccess 8.3.1 Advantech WebAccess 8.3 Advantech WebAccess 8.2 Advantech WebAccess 8.1 Advantech WebAccess 8 |
| Not Vulnerable: |
Advantech WebAccess 8.3.3 |
Discussion
Advantech ICSA-18-296-01 WebAccess Multiple Security Vulnerabilities
Advantech WebAccess is prone to the following security vulnerabilities:
1. A stack-based buffer overflow vulnerability
2. A directory-traversal vulnerability
3. An arbitrary-file-deletion vulnerability
4. A remote-privilege escalation vulnerability
An attacker can exploit these issues to execute arbitrary code in the context of the application, modify and delete files, use directory-traversal sequences (â??../â??) to retrieve arbitrary files, escalate privileges and perform certain unauthorized actions. This may aid in further attacks.
Advantech WebAccess 8.3.1 and prior versions are vulnerable.
Advantech WebAccess is prone to the following security vulnerabilities:
1. A stack-based buffer overflow vulnerability
2. A directory-traversal vulnerability
3. An arbitrary-file-deletion vulnerability
4. A remote-privilege escalation vulnerability
An attacker can exploit these issues to execute arbitrary code in the context of the application, modify and delete files, use directory-traversal sequences (â??../â??) to retrieve arbitrary files, escalate privileges and perform certain unauthorized actions. This may aid in further attacks.
Advantech WebAccess 8.3.1 and prior versions are vulnerable.
Exploit / POC
Advantech ICSA-18-296-01 WebAccess Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Advantech ICSA-18-296-01 WebAccess Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Advantech ICSA-18-296-01 WebAccess Multiple Security Vulnerabilities
References:
References:
- Advantech WebAccess Homepage (Advantech)
- Advisory (ICSA-18-296-01) Advantech WebAccess (CERT)