upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-16-173-01 | third party advisory us government resource |
http://www.zerodayinitiative.com/advisories/ZDI-16-429 | vdb entry third party advisory |