CVE-2020-13551: High severity advantech webaccess/scada vulnerability
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13551?
CVE-2020-13551 has a high severity rating, as it involves local privilege escalation that can lead to code execution with NT SYSTEM privileges.
How do I fix CVE-2020-13551?
To mitigate CVE-2020-13551, update Advantech WebAccess/SCADA to the latest version that addresses this vulnerability.
What systems are affected by CVE-2020-13551?
CVE-2020-13551 specifically affects Advantech WebAccess/SCADA version 9.0.1.
Can CVE-2020-13551 be exploited remotely?
CVE-2020-13551 is considered a local privilege escalation vulnerability and cannot be exploited remotely.
What does CVE-2020-13551 allow an attacker to do?
CVE-2020-13551 allows an attacker to execute code with elevated privileges by replacing binaries or modules in the PostgreSQL executable.