First published: Wed Oct 27 2021(Updated: )
WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources monitored and controlled by the WebAccess/NMS, as well as IP addresses and names of all the devices managed via WebAccess/NMS.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess/NMS | <=3.0.3 | |
Advantech WebAccess/NMS |
Advantech recommends updating to Version 3.0.3
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32951 has a medium severity level due to its improper authentication vulnerability.
To fix CVE-2021-32951, upgrade the WebAccess/NMS to version 3.0.3_Build6299 or later.
CVE-2021-32951 may allow unauthorized users to access monitored resources and device details.
WebAccess/NMS versions prior to v3.0.3_Build6299 are affected by CVE-2021-32951.
Currently, applying the recommended upgrade is the best way to mitigate the risks from CVE-2021-32951.