First published: Thu Apr 09 2020(Updated: )
Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to gain access to sensitive information.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess/NMS | <3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-10623 is considered to be moderate, as it allows low-privilege attackers to perform SQL injection.
To fix CVE-2020-10623, update your Advantech WebAccess/NMS software to version 3.0.2 or later.
Advantech WebAccess/NMS versions prior to 3.0.2 are affected by CVE-2020-10623.
CVE-2020-10623 is associated with SQL injection attacks that can lead to unauthorized access to sensitive information.
CVE-2020-10623 can be exploited by attackers with low privileges.