First published: Wed Sep 18 2019(Updated: )
In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and may allow arbitrary file deletion and remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess | <=8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13552 is a vulnerability in WebAccess versions 8.4.1 and prior that allows arbitrary file deletion and remote code execution.
CVE-2019-13552 has a severity rating of 8.8, indicating a high severity.
The affected software is Advantech WebAccess versions 8.4.1 and prior.
CVE-2019-13552 is associated with CWE-77, which is a code injection vulnerability.
To fix CVE-2019-13552, you should update to a version of WebAccess that is later than 8.4.1.