CVE-2018-15706: Path Traversal
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Advantech WebAccess?
The vulnerability ID for Advantech WebAccess is CVE-2018-15706.
What is the severity of CVE-2018-15706?
The severity of CVE-2018-15706 is medium with a CVSS score of 6.5.
What is the affected software version of CVE-2018-15706?
The affected software versions of CVE-2018-15706 are Advantech WebAccess 8.3.1 and 8.3.2.
How can a remote authenticated attacker exploit CVE-2018-15706?
A remote authenticated attacker can exploit CVE-2018-15706 by using the WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.
Where can I find more information about CVE-2018-15706?
You can find more information about CVE-2018-15706 at the following link: https://www.tenable.com/security/research/tra-2018-35