First published: Tue May 15 2018(Updated: )
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a TFTP application has unrestricted file uploads to the web application without authorization, which may allow an attacker to execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebOP | <=8.2_20170817 | |
Advantech WebOP | <=8.3.0 | |
Advantech WebAccess Dashboard | <=2.0.15 | |
Advantech WebAccess/SCADA | <8.3.1 | |
Advantech WebAccess/NMS | <=2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7505 has a critical severity rating due to the potential for unrestricted file uploads.
To fix CVE-2018-7505, upgrade to Advantech WebAccess version V8.3.1 or later, WebAccess Dashboard version V2.0.16 or later, and WebAccess/NMS version 2.0.4 or later.
CVE-2018-7505 affects Advantech WebAccess versions up to 8.2_20170817, WebAccess Dashboard versions up to 2.0.15, and WebAccess Scada Node versions prior to 8.3.1.
CVE-2018-7505 can be exploited through an unrestricted file upload attack, potentially allowing unauthorized file access and execution.
If immediate patching is not possible, restrict access to the TFTP application and monitor for suspicious upload activities.