In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an information exposure vulnerability through directory listing has been identified, which may allow an attacker to find important files that are not normally visible.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NAdvantech Webaccess
APPAdvantech≤ 8.2_20170817≤ 8.3.0Advantech Webaccess Dashboard
APPAdvantech≤ 2.0.15Advantech Webaccess\/nms
APPAdvantech≤ 2.0.3Advantech Webaccess Scada
APPAdvantech< 8.3.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2021-33023CRITICAL9.8PL ✓ten sam produkt
Heap-based buffer overflow w Advantech WebAccess umożliwiający RCE
CVE-2021-38389CRITICAL9.8PL ✓ten sam produkt
Stack-based buffer overflow w Advantech WebAccess umożliwiający RCE
CVE-2021-38408CRITICAL9.8PL ✓ten sam produkt
Stack-based buffer overflow w Advantech WebAccess umożliwiający RCE
CVE-2020-12019CRITICAL9.8PL ✓ten sam produkt
Stack-based buffer overflow umożliwiający RCE w Advantech WebAccess Node
CVE-2020-12002CRITICAL9.8PL ✓ten sam produkt
RCE przez wiele podatności buffer overflow w Advantech WebAccess Node