vendor:
WebAccess
by:
Chris Lyne
9.8
CVSS
CRITICAL
SQL Injection Authentication Bypass
89
CWE
Product Name: WebAccess
Affected Version From: Advantech WebAccess 8.0-2015.08.16 and earlier versions
Affected Version To: Advantech WebAccess 8.0-2015.08.16
Patch Exists: YES
Related CWE: CVE-2017-16716
CPE: a:advantech:webaccess
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows Server 2008 R2 Enterprise 64-bit
2018
Advantech WebAccess BWSCADARest Login Method SQL Injection Authentication Bypass Vulnerability
Advantech WebAccess BWSCADARest Login Method is vulnerable to SQL Injection Authentication Bypass. An attacker can exploit this vulnerability to bypass authentication and gain access to the application. This vulnerability affects Advantech WebAccess 8.0-2015.08.16 and earlier versions.
Mitigation:
Advantech has released a patch to address this vulnerability. Users are advised to upgrade to the latest version of Advantech WebAccess.