First published: Mon Mar 11 2013(Updated: )
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via a full pathname in an argument to the sub_401A90 CreateFileW function.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech Advantech Studio | =6.1 | |
Advantech Advantech Studio | =6.1-sp6_61.6.01.05 | |
InduSoft Web Studio | =6.1 | |
InduSoft Web Studio | =6.1-sp6 | |
InduSoft Web Studio | =7.0 | |
InduSoft Web Studio | =7.0b2-hotfix7.0.01.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1627 is rated as a medium severity vulnerability.
CVE-2013-1627 allows remote attackers to read arbitrary files using a full pathname due to an absolute path traversal vulnerability.
CVE-2013-1627 affects InduSoft Studio versions 7.0 and earlier, as well as Advantech Studio versions 7.0 and earlier.
To mitigate CVE-2013-1627, it is recommended to update to the latest version of the affected software, if available.
Yes, CVE-2013-1627 can be exploited by remote attackers, making it critical to secure affected systems.