First published: Fri Apr 05 2019(Updated: )
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplied data, may allow remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess | <=8.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-6552 is critical with a CVSS score of 9.8.
The affected software for CVE-2019-6552 is Advantech WebAccess/SCADA versions 8.3.5 and prior.
CVE-2019-6552 is a command injection vulnerability.
CVE-2019-6552 can be exploited by an attacker who has access to the affected system, as they can inject malicious commands to execute remote code.
Yes, it is recommended to update Advantech WebAccess/SCADA to version 8.3.6 or later to fix CVE-2019-6552.