CVE-2021-38431: Advantech WebAccess SCADA
An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Advantech WebAccess SCADAto a version that resolves this vulnerability.Fixed in 9.1.1 - Upgrade
Upgrade
Advantech WebAccess SCADAto a version that resolves this vulnerability.Fixed in 9.0.3
Event History
Frequently Asked Questions
What is CVE-2021-38431 vulnerability?
An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can utilize API functions to reveal project names and paths from other users.
How severe is CVE-2021-38431?
The severity of CVE-2021-38431 is considered medium with a CVSS score of 4.3.
How can I mitigate CVE-2021-38431?
To mitigate CVE-2021-38431, users should update Advantech WebAccess SCADA to version 9.0.4 or later.
What is the CWE associated with CVE-2021-38431?
The CWE associated with CVE-2021-38431 is CWE-862.