CVE-2023-2866

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
07/06/2023
Last modified:
15/06/2023

Description

<br /> If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server. <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:advantech:webaccess:8.4.5:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools