First published: Thu Jan 25 2018(Updated: )
A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess/SCADA | <8.2_20170817 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5443 has been classified as a critical vulnerability due to its potential for remote exploitation through SQL injection.
To fix CVE-2018-5443, upgrade Advantech WebAccess/SCADA to version 8.2_20170817 or later.
CVE-2018-5443 affects any SQL command inputs that are not properly sanitized in Advantech WebAccess/SCADA.
Organizations using Advantech WebAccess/SCADA versions prior to 8.2_20170817 are at risk due to CVE-2018-5443.
An attacker exploiting CVE-2018-5443 can execute arbitrary SQL commands against the database, potentially gaining unauthorized access to sensitive data.