CVE-2018-15705: Path Traversal
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15705?
CVE-2018-15705 is a vulnerability in Advantech WebAccess 8.3.1 and 8.3.2 that allows remote authenticated attackers to write or overwrite any file on the filesystem.
How does CVE-2018-15705 work?
CVE-2018-15705 works by exploiting a directory traversal vulnerability in the writeFile API of Advantech WebAccess, allowing attackers to remotely execute arbitrary code.
What is the severity level of CVE-2018-15705?
The severity level of CVE-2018-15705 is high, with a CVSS score of 6.5.
Which versions of Advantech WebAccess are affected by CVE-2018-15705?
CVE-2018-15705 affects Advantech WebAccess 8.3.1 and 8.3.2.
How can I mitigate CVE-2018-15705?
To mitigate CVE-2018-15705, it is recommended to update Advantech WebAccess to a version that addresses the vulnerability or apply any patches or fixes provided by the vendor.