In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a TFTP application has unrestricted file uploads to the web application without authorization, which may allow an attacker to execute arbitrary code.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/104190 | vdb entry third party advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-18-135-01 | third party advisory us government resource |