CVE-2023-2866: Advantech WebAccess Insufficient Type Distinction
Published Jun 7, 2023
·Updated
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.
Affected Software
2 affected components
Advantech WebAccess/SCADA: version 8.4.5
Advantech WebAccess=8.4.5
Remediation
Information
Advantech released a new version V9.1.4 https://www.advantech.com/en/support/details/installation to address the problem by not including these files.
Event History
Jun 7, 2023
CVE Published
via MITRE·08:12 PM
Data Sourced
via MITRE·08:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-2866.
2
What is the severity rating of CVE-2023-2866?
CVE-2023-2866 has a severity rating of 7.8 (High).
3
What software version is affected by CVE-2023-2866?
Advantech WebAccess version 8.4.5 is affected by CVE-2023-2866.
4
How can an attacker exploit this vulnerability?
An attacker can exploit CVE-2023-2866 by tricking an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5.
5
What is the potential impact of this vulnerability?
The potential impact of CVE-2023-2866 is that it allows the attacker to gain full control of the SCADA server using a web shell.