Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perform actions at a system administrator level.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1041939 | third party advisory vdb entry |
https://ics-cert.us-cert.gov/advisories/ICSA-18-296-01%2C | |
http://www.securityfocus.com/bid/105728 | third party advisory vdb entry |