Advantech WebAccess Multiple Security Vulnerabilities
BID:107847
CVE-2019-3940 | CVE-2019-3941 |Info
Advantech WebAccess Multiple Security Vulnerabilities
| Bugtraq ID: | 107847 |
| Class: | Design Error |
| CVE: |
CVE-2019-3940 CVE-2019-3941 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 03 2019 12:00AM |
| Updated: | Apr 03 2019 12:00AM |
| Credit: | Tenable |
| Vulnerable: |
Advantech WebAccess/SCADA 8.3.4 |
| Not Vulnerable: |
Advantech WebAccess/SCADA 8.3.5 |
Discussion
Advantech WebAccess Multiple Security Vulnerabilities
Advantech WebAccess is prone to the following security vulnerabilities:
1. An arbitrary file-download vulnerability
2. An arbitrary file-upload vulnerability
An attacker can exploit these issues to execute arbitrary code in the context of the application, modify and delete files and perform certain unauthorized actions. This may aid in further attacks.
Advantech WebAccess 8.3.4 is vulnerable; other versions may also be affected.
Advantech WebAccess is prone to the following security vulnerabilities:
1. An arbitrary file-download vulnerability
2. An arbitrary file-upload vulnerability
An attacker can exploit these issues to execute arbitrary code in the context of the application, modify and delete files and perform certain unauthorized actions. This may aid in further attacks.
Advantech WebAccess 8.3.4 is vulnerable; other versions may also be affected.
Exploit / POC
Advantech WebAccess Multiple Security Vulnerabilities
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Advantech WebAccess Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Advantech WebAccess Multiple Security Vulnerabilities
References:
References: