First published: Fri Jan 15 2016(Updated: )
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebOP | <=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0854 is classified as a high severity vulnerability due to its potential for remote file upload and arbitrary code execution.
To fix CVE-2016-0854, upgrade Advantech WebAccess to version 8.1 or later which addresses this vulnerability.
CVE-2016-0854 can be exploited to perform remote code execution and upload malicious files to the server.
CVE-2016-0854 affects all versions of Advantech WebAccess prior to version 8.1.
Yes, you can restrict file upload operations and implement file type validations as a temporary workaround for CVE-2016-0854.