CVE-2023-32540: Code Injection
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-32540.
What is the severity of CVE-2023-32540?
The severity of CVE-2023-32540 is critical with a score of 9.8.
Which software versions are affected by CVE-2023-32540?
Advantech WebAccss/SCADA versions up to and including 9.1.3 are affected by CVE-2023-32540.
What can an attacker do with CVE-2023-32540?
The attacker can overwrite any file in the operating system, inject code into an XLS file, and modify the file extension.
Is there a fix available for CVE-2023-32540?
At the moment, there is no information available regarding a fix for CVE-2023-32540. It is recommended to follow security advisories and updates from Advantech.