vendor:
WebAccess
by:
Nassim Asrir
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: WebAccess
Affected Version From: 8.3.2000
Affected Version To: 8.3.2000
Patch Exists: NO
Related CWE: CVE-2018-6911
CPE: a:advantech:webaccess:8.3.0
Platforms Tested: Windows
2018
Advantech WebAccess Node8.3.0 “AspVBObj.dll” – Remote Code Execution
The VBWinExec function in NodeAspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument.
Mitigation:
Apply the latest patch or upgrade to a non-vulnerable version.