CVE-2019-3940: Malicious File Upload
Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3940?
CVE-2019-3940 is a vulnerability in Advantech WebAccess 8.3.4 that allows for file upload attacks via an unauthenticated remote procedure call (RPC) call.
How can an attacker exploit CVE-2019-3940?
An unauthenticated attacker can exploit CVE-2019-3940 by using a file upload attack via an unauthenticated RPC call, allowing them to execute arbitrary code.
What is the severity of CVE-2019-3940?
CVE-2019-3940 has a severity rating of 9.8 (Critical).
How can I fix CVE-2019-3940?
To fix CVE-2019-3940, Advantech WebAccess 8.3.4 users should apply the latest security patches and updates provided by the vendor.
Where can I find more information about CVE-2019-3940?
More information about CVE-2019-3940 can be found at the following references: [SecurityFocus](http://www.securityfocus.com/bid/107847) and [Tenable](https://www.tenable.com/security/research/tra-2019-15).