First published: Wed Oct 31 2018(Updated: )
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess | =8.3.1 | |
Advantech WebAccess | =8.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15705 is a vulnerability in Advantech WebAccess 8.3.1 and 8.3.2 that allows remote authenticated attackers to write or overwrite any file on the filesystem.
CVE-2018-15705 works by exploiting a directory traversal vulnerability in the writeFile API of Advantech WebAccess, allowing attackers to remotely execute arbitrary code.
The severity level of CVE-2018-15705 is high, with a CVSS score of 6.5.
CVE-2018-15705 affects Advantech WebAccess 8.3.1 and 8.3.2.
To mitigate CVE-2018-15705, it is recommended to update Advantech WebAccess to a version that addresses the vulnerability or apply any patches or fixes provided by the vendor.