Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.tenable.com/security/research/tra-2019-15 | third party advisory |
http://www.securityfocus.com/bid/107847 | third party advisory vdb entry |