Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.tenable.com/security/research/tra-2019-15 | third party advisory exploit |
http://www.securityfocus.com/bid/107847 | vdb entry third party advisory |