CVE-2017-12713: High severity Advantech WebAccess vulnerability
Published Aug 30, 2017
·Updated
An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.220170817. Multiple files and folders with ACLs that affect other users are allowed to be modified by non-administrator accounts.
Affected Software
1 affected component
Advantech WebAccess<=8.2
Event History
Aug 30, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-12713?
CVE-2017-12713 has a medium severity rating due to improper permissions on critical resources.
2
How do I fix CVE-2017-12713?
To fix CVE-2017-12713, update Advantech WebAccess to version 8.2_20170817 or later.
3
What versions of Advantech WebAccess are affected by CVE-2017-12713?
Advantech WebAccess versions prior to 8.2_20170817 are affected by CVE-2017-12713.
4
What type of vulnerability is CVE-2017-12713?
CVE-2017-12713 is classified as an Incorrect Permission Assignment for Critical Resource issue.
5
Can non-administrator accounts modify files due to CVE-2017-12713?
Yes, non-administrator accounts can modify certain files and folders that have improper ACLs due to CVE-2017-12713.