In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an information exposure vulnerability through directory listing has been identified, which may allow an attacker to find important files that are not normally visible.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NAdvantech Webaccess
APPAdvantech≤ 8.2_20170817≤ 8.3.0Advantech Webaccess Dashboard
APPAdvantech≤ 2.0.15Advantech Webaccess\/nms
APPAdvantech≤ 2.0.3Advantech Webaccess Scada
APPAdvantech< 8.3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-33023CRITICAL9.8PL ✓same product
Heap-based buffer overflow w Advantech WebAccess umożliwiający RCE
CVE-2021-38389CRITICAL9.8PL ✓same product
Stack-based buffer overflow w Advantech WebAccess umożliwiający RCE
CVE-2021-38408CRITICAL9.8PL ✓same product
Stack-based buffer overflow w Advantech WebAccess umożliwiający RCE
CVE-2020-12019CRITICAL9.8PL ✓same product
Stack-based buffer overflow umożliwiający RCE w Advantech WebAccess Node
CVE-2020-12002CRITICAL9.8PL ✓same product
RCE przez wiele podatności buffer overflow w Advantech WebAccess Node