vendor:
WebAccess
by:
Chris Lyne
9.8
CVSS
CRITICAL
Directory Traversal RCE
22
CWE
Product Name: WebAccess
Affected Version From: Advantech WebAccess 8.2-2017.08.18
Affected Version To: Advantech WebAccess 8.3
Patch Exists: YES
Related CWE: CVE-2017-16720
CPE: a:advantech:webaccess
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows Server 2008 R2 Enterprise 64-bit
2018
Advantech WebAccess < 8.3 webvrpcs Directory Traversal RCE Vulnerability
Advantech WebAccess versions prior to 8.3 are vulnerable to a directory traversal attack which allows an attacker to execute arbitrary code on the target system. This vulnerability is due to a lack of proper validation of user-supplied input when handling requests to the webvrpcs directory. An attacker can exploit this vulnerability by sending a specially crafted request containing directory traversal characters to the webvrpcs directory. This will allow the attacker to execute arbitrary code on the target system.
Mitigation:
Advantech has released a patch to address this vulnerability. Users are advised to upgrade to Advantech WebAccess version 8.3 or later.