WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the installation is complete. This could allow an attacker to run elevated arbitrary code.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-18-298-02 | third party advisory us government resource |
http://www.securityfocus.com/bid/105736 | vdb entry third party advisory |
http://www.securitytracker.com/id/1041957 | vdb entry third party advisory |