CVE-2016-0854: Critical severity advantech webop vulnerability
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0854?
CVE-2016-0854 is classified as a high severity vulnerability due to its potential for remote file upload and arbitrary code execution.
How do I fix CVE-2016-0854?
To fix CVE-2016-0854, upgrade Advantech WebAccess to version 8.1 or later which addresses this vulnerability.
What types of attacks can occur due to CVE-2016-0854?
CVE-2016-0854 can be exploited to perform remote code execution and upload malicious files to the server.
Which versions of Advantech WebAccess are affected by CVE-2016-0854?
CVE-2016-0854 affects all versions of Advantech WebAccess prior to version 8.1.
Is there a workaround for CVE-2016-0854 until a fix is applied?
Yes, you can restrict file upload operations and implement file type validations as a temporary workaround for CVE-2016-0854.