First published: Fri May 08 2020(Updated: )
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An improper validation vulnerability exists that could allow an attacker to inject specially crafted input into memory where it can be executed.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess/SCADA | ||
Advantech WebAccess | <=8.4.4 | |
Advantech WebAccess | =9.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this advisory is CVE-2020-12022.
The severity of CVE-2020-12022 is critical with a score of 9.8.
The Advantech WebAccess/SCADA software versions 8.4.4 and 9.0.0 are affected by CVE-2020-12022.
An attacker can exploit CVE-2020-12022 by executing arbitrary code on affected installations of Advantech WebAccess/SCADA without requiring authentication.
To fix CVE-2020-12022, it is recommended to apply the latest security patches or updates provided by Advantech for WebAccess/SCADA.