Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.
References
| Link | Resource |
|---|---|
| https://www.tenable.com/security/research/tra-2019-15 | Third Party Advisory |
Configurations
Information
Published : 2020-04-01 10:15
Updated : 2020-04-02 08:30
NVD link : CVE-2019-3942
Mitre link : CVE-2019-3942
JSON object : View
CWE
CWE-522
Insufficiently Protected Credentials
Products Affected
advantech
- webaccess


