Advantech WebAccess/SCADA ICSA-19-092-01 Multiple Security Vulnerabilities
BID:107675
Info
Advantech WebAccess/SCADA ICSA-19-092-01 Multiple Security Vulnerabilities
| Bugtraq ID: | 107675 |
| Class: | Unknown |
| CVE: |
CVE-2019-6552 CVE-2019-6554 CVE-2019-6550 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2019 12:00AM |
| Updated: | Apr 02 2019 12:00AM |
| Credit: | Mat Powell and Natnael Samson (@NattiSamson) working with Trend Micro�??s Zero Day Initiative |
| Vulnerable: |
Advantech WebAccess/SCADA 8.3.5 Advantech WebAccess/SCADA 8.3.4 Advantech WebAccess/SCADA 8.3.2 Advantech WebAccess/SCADA 8.3 |
| Not Vulnerable: |
Advantech WebAccess/SCADA 8.4 |
Discussion
Advantech WebAccess/SCADA ICSA-19-092-01 Multiple Security Vulnerabilities
Advantech WebAccess/SCADA is prone to the following vulnerabilities:
1. Multiple command-injection vulnerabilities
2. A denial-of-service vulnerability
3. Multiple stack-based buffer-overflow vulnerabilities
An attacker can exploit these issues to inject and execute arbitrary commands in the context of the application. Failed exploit attempts will result in denial-of-service conditions.
Advantech WebAccess/SCADA version 8.3.5 and prior are vulnerable.
Advantech WebAccess/SCADA is prone to the following vulnerabilities:
1. Multiple command-injection vulnerabilities
2. A denial-of-service vulnerability
3. Multiple stack-based buffer-overflow vulnerabilities
An attacker can exploit these issues to inject and execute arbitrary commands in the context of the application. Failed exploit attempts will result in denial-of-service conditions.
Advantech WebAccess/SCADA version 8.3.5 and prior are vulnerable.
Solution / Fix
Advantech WebAccess/SCADA ICSA-19-092-01 Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Advantech WebAccess/SCADA ICSA-19-092-01 Multiple Security Vulnerabilities
References:
References:
- Advantech Home Page (Advantech)
- Advantech WebAccess/SCADA Product Page (Advantech)
- Advisory (ICSA-19-092-01) Advantech WebAccess/SCADA ()