CVE-2018-5443: SQL Injection
A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.220170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Advantech WebAccess/SCADAto a version that resolves this vulnerability.Fixed in V8.2_20170817
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5443?
CVE-2018-5443 has been classified as a critical vulnerability due to its potential for remote exploitation through SQL injection.
How do I fix CVE-2018-5443?
To fix CVE-2018-5443, upgrade Advantech WebAccess/SCADA to version 8.2_20170817 or later.
What types of input are affected by CVE-2018-5443?
CVE-2018-5443 affects any SQL command inputs that are not properly sanitized in Advantech WebAccess/SCADA.
Who is affected by CVE-2018-5443?
Organizations using Advantech WebAccess/SCADA versions prior to 8.2_20170817 are at risk due to CVE-2018-5443.
What can an attacker do with CVE-2018-5443?
An attacker exploiting CVE-2018-5443 can execute arbitrary SQL commands against the database, potentially gaining unauthorized access to sensitive data.