CVE-2019-6552: OS Command Injection
Published Apr 5, 2019
·Updated
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplied data, may allow remote code execution.
Affected Software
1 affected component
Advantech WebAccess<=8.3.5
Event History
Apr 5, 2019
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-6552?
The severity of CVE-2019-6552 is critical with a CVSS score of 9.8.
2
What is the affected software for CVE-2019-6552?
The affected software for CVE-2019-6552 is Advantech WebAccess/SCADA versions 8.3.5 and prior.
3
What is the vulnerability type of CVE-2019-6552?
CVE-2019-6552 is a command injection vulnerability.
4
How can CVE-2019-6552 be exploited?
CVE-2019-6552 can be exploited by an attacker who has access to the affected system, as they can inject malicious commands to execute remote code.
5
Is there a fix available for CVE-2019-6552?
Yes, it is recommended to update Advantech WebAccess/SCADA to version 8.3.6 or later to fix CVE-2019-6552.