CVE-2019-13552: Command Injection
Published Sep 18, 2019
·Updated
In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and may allow arbitrary file deletion and remote code execution.
Affected Software
1 affected component
Advantech WebAccess<=8.4.1
Event History
Sep 18, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-13552?
CVE-2019-13552 is a vulnerability in WebAccess versions 8.4.1 and prior that allows arbitrary file deletion and remote code execution.
2
How severe is CVE-2019-13552?
CVE-2019-13552 has a severity rating of 8.8, indicating a high severity.
3
What is the affected software?
The affected software is Advantech WebAccess versions 8.4.1 and prior.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-13552?
CVE-2019-13552 is associated with CWE-77, which is a code injection vulnerability.
5
How can I fix CVE-2019-13552?
To fix CVE-2019-13552, you should update to a version of WebAccess that is later than 8.4.1.