CVE-2019-13558: Code Injection
In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote code execution, data exfiltration, or cause a system crash.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13558?
CVE-2019-13558 is a vulnerability in Advantech WebAccess versions 8.4.1 and prior that allows remote code execution, data exfiltration, or system crash.
How severe is CVE-2019-13558?
CVE-2019-13558 has a severity rating of 9.8, which is classified as critical.
How does CVE-2019-13558 affect Advantech WebAccess?
CVE-2019-13558 affects Advantech WebAccess versions 8.4.1 and prior, potentially allowing remote code execution, data exfiltration, or system crash.
How can I fix CVE-2019-13558?
To fix CVE-2019-13558, users should update Advantech WebAccess to a version beyond 8.4.1.
Where can I find more information about CVE-2019-13558?
More information about CVE-2019-13558 can be found at the following link: [US-CERT Advisory ICSA-19-260-01](https://www.us-cert.gov/ics/advisories/icsa-19-260-01)