QID 590523
Date Published: 2021-09-08
QID 590523: Advantech WebAccess Supervisory control and data acquisition (SCADA) Multiple Vulnerabilities (ICSA-21-217-04)
AFFECTED PRODUCTS
The following versions of WebAccess/SCADA, a browser-based SCADA software package, are affected:
WebAccess/SCADA versions prior to 8.4.5
WebAccess/SCADA versions prior to 9.0.1
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
Successful exploitation of these vulnerabilities could allow an attacker to hijack a users cookie/session tokens, gain unauthorized access to files and directories, and execute arbitrary code.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-217-04 for affected packages and patching details.
Vendor References
- ICSA-21-217-04 -
www.us-cert.gov/ics/advisories/ICSA-21-217-04
CVEs related to QID 590523
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-21-217-04 |
|