CVE-2018-8841: High severity Advantech WebAccess vulnerability
In Advantech WebAccess versions V8.220170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an improper privilege management vulnerability may allow an authenticated user to modify files when read access should only be given to the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8841?
CVE-2018-8841 is classified as a high-severity vulnerability due to its potential impact on system privilege management.
How do I fix CVE-2018-8841?
To fix CVE-2018-8841, upgrade to Advantech WebAccess versions later than V8.2_20170817 and V8.3.0, or the respective updated versions of affected applications.
Which versions are affected by CVE-2018-8841?
CVE-2018-8841 affects Advantech WebAccess versions V8.2_20170817 and prior, V8.3.0 and prior, and various Dashboard and SCADA versions prior to specified thresholds.
What types of vulnerabilities does CVE-2018-8841 represent?
CVE-2018-8841 represents an improper privilege management vulnerability that can impact authenticated users.
Is CVE-2018-8841 exploitable remotely?
CVE-2018-8841 requires authenticated access, making it less susceptible to remote exploitation but still a significant risk for attackers with network access.