First published: Fri Jan 28 2022(Updated: )
A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech Wise-paas\/ota | =3.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-40397 is critical.
The privilege escalation vulnerability in CVE-2021-40397 allows an attacker to replace a specially-crafted file in the system and escalate privileges to NT SYSTEM authority.
Advantech WISE-PaaS/OTA Server version 3.0.9 is affected by CVE-2021-40397.
Apply the necessary patch or upgrade to a fixed version (if available) provided by Advantech Wise-paas/ota.
You can find more information about CVE-2021-40397 on the Talos Intelligence vulnerability report: [https://talosintelligence.com/vulnerability_reports/TALOS-2021-1409](https://talosintelligence.com/vulnerability_reports/TALOS-2021-1409).