CVE-2023-32540
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
06/06/2023
Last modified:
12/06/2023
Description
<br />
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.<br />
<br />
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:advantech:webaccess\/scada:*:*:*:*:*:*:*:* | 9.1.3 (including) |
To consult the complete list of CPE names with products and versions, see this page



