CVE-2023-1437

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/08/2023
Last modified:
01/02/2024

Description

All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:advantech:webaccess\/scada:*:*:*:*:*:*:*:* 9.1.4 (excluding)


References to Advisories, Solutions, and Tools