CVE-2018-7505: Malicious File Upload
In Advantech WebAccess versions V8.220170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a TFTP application has unrestricted file uploads to the web application without authorization, which may allow an attacker to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7505?
CVE-2018-7505 has a critical severity rating due to the potential for unrestricted file uploads.
How do I fix CVE-2018-7505?
To fix CVE-2018-7505, upgrade to Advantech WebAccess version V8.3.1 or later, WebAccess Dashboard version V2.0.16 or later, and WebAccess/NMS version 2.0.4 or later.
What products are affected by CVE-2018-7505?
CVE-2018-7505 affects Advantech WebAccess versions up to 8.2_20170817, WebAccess Dashboard versions up to 2.0.15, and WebAccess Scada Node versions prior to 8.3.1.
What kind of attack can exploit CVE-2018-7505?
CVE-2018-7505 can be exploited through an unrestricted file upload attack, potentially allowing unauthorized file access and execution.
Is there a workaround for CVE-2018-7505 if immediate patching is not possible?
If immediate patching is not possible, restrict access to the TFTP application and monitor for suspicious upload activities.