WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code.
2018-10-31T22:29:00.413
2024-11-21T03:51:18.680
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:C/A:C
8.0
9.2
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | advantech | webaccess | 8.3.1 | Yes |
| Application | advantech | webaccess | 8.3.2 | Yes |