CVE-2018-17908

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
29/10/2018
Last modified:
09/10/2019

Description

WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the installation is complete. This could allow an attacker to run elevated arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:advantech:webaccess:*:*:*:*:*:*:*:* 8.3.2 (including)