CVE-2020-12026: Advantech WebAccess/SCADA ViewSrv IOCTL 0x0000277d Directory Traversal Remote Code Execution Vulnerability
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Advantech WebAccess/SCADA. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of IOCTL 0x0000277d in ViewSrv.dll. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of Administrator.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12026?
CVE-2020-12026 is a vulnerability in Advantech WebAccess/SCADA that allows remote attackers to execute arbitrary code.
How severe is CVE-2020-12026?
CVE-2020-12026 has a severity score of 9.8, which is considered critical.
What software is affected by CVE-2020-12026?
Advantech WebAccess/SCADA versions 8.4.4 and 9.0.0 are affected by CVE-2020-12026.
How can CVE-2020-12026 be exploited?
CVE-2020-12026 can be exploited by remote attackers without authentication.
Are there any references for CVE-2020-12026?
Yes, you can find more information about CVE-2020-12026 at the following references:\n1. [US-CERT Advisory ICSA-20-128-36](https://www.us-cert.gov/ics/advisories/icsa-20-128-36)\n2. [Zero Day Initiative Advisory ZDI-20-626](https://www.zerodayinitiative.com/advisories/ZDI-20-626/)\n3. [US-CERT Advisory ICSA-20-128-01](https://www.us-cert.gov/ics/advisories/icsa-20-128-01)