vendor:
WebAccess SCADA
by:
Chris Lyne
5.4
CVSS
MEDIUM
Remote Code Execution
78
CWE
Product Name: WebAccess SCADA
Affected Version From: 8.3.2
Affected Version To: 8.3.2
Patch Exists: YES
Related CWE: CVE-2018-15705, CVE-2018-15707
CPE: a:advantech:webaccess_scada:8.3.2
Metasploit:
https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2017-15705/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2017-15705/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2017-15705/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2017-15705/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2017-15705/
Other Scripts:
N/A
Platforms Tested: Windows Server 2008 R2
2018
Advantech WebAccess SCADA 8.3.2 – Remote Code Execution
This code exploits two vulnerabilities to gain remote code execution with Administrator privileges: CVE-2018-15707 to steal credentials (XSS). User-interaction required. CVE-2018-15705 to write an ASP file to the server.
Mitigation:
Ensure that all web applications are patched with the latest security updates and that all users are using strong passwords.