Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplied data, may allow remote code execution.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-19-092-01 | Third Party Advisory US Government Resource |
Configurations
Information
Published : 2019-04-05 12:29
Updated : 2020-10-06 07:03
NVD link : CVE-2019-6552
Mitre link : CVE-2019-6552
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
advantech
- webaccess