CVE-2020-12010: Path Traversal
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12010?
CVE-2020-12010 is a vulnerability found in Advantech WebAccess Node, versions 8.4.4 and prior, as well as version 9.0.0, which allows an authenticated user to delete files outside of the application's control.
How severe is CVE-2020-12010?
CVE-2020-12010 has a severity rating of 7.1, which is considered high.
What is the affected software by CVE-2020-12010?
The affected software by CVE-2020-12010 is Advantech WebAccess, versions 8.4.4 and prior, as well as version 9.0.0.
How can an authenticated user exploit CVE-2020-12010?
An authenticated user can exploit CVE-2020-12010 by using a specially crafted file to delete files outside of the application's control.
Where can I find more information about CVE-2020-12010?
You can find more information about CVE-2020-12010 at the following link: https://www.us-cert.gov/ics/advisories/icsa-20-128-01