First published: Tue Feb 23 2021(Updated: )
The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess/SCADA | <9.0.1 | |
Advantech WebAccess/SCADA |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25161 is rated as high severity due to the potential for remote code execution as an administrator.
To fix CVE-2020-25161, upgrade to a version of WebAccess/SCADA later than 9.0.
The impacts of CVE-2020-25161 include unauthorized access to system resources and the ability to execute code remotely.
CVE-2020-25161 affects Advantech WebAccess/SCADA versions 9.0 and prior.
There are no established workarounds for CVE-2020-25161; upgrading is the recommended action.