First published: Thu Apr 09 2020(Updated: )
An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess/NMS | <3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10631 is rated as high severity due to the potential for unauthorized file access and deletion.
To fix CVE-2020-10631, upgrade Advantech WebAccess/NMS to version 3.0.2 or later.
CVE-2020-10631 allows attackers to exploit vulnerabilities via specially crafted URLs to read or delete files outside the WebAccess/NMS control.
CVE-2020-10631 affects all versions of Advantech WebAccess/NMS prior to version 3.0.2.
If upgrading is not possible, consider implementing firewall rules or security measures to mitigate exposure to CVE-2020-10631.