CVE-2023-4215: Advantech WebAccess Debug Messages Revealing Unnecessary Information
Published Oct 16, 2023
·Updated
Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.
Affected Software
1 affected component
Advantech WebAccess=9.1.3
Remediation
Information
Advantech recommends users update WebAccess to Version 9.1.4 https://www.advantech.com/en/support/details/installation
Event History
Oct 16, 2023
CVE Published
via MITRE·11:40 PM
Data Sourced
via MITRE·11:40 PM
RemedyDescriptionSeverityWeakness
Oct 17, 2023
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-4215?
CVE-2023-4215 is a vulnerability in Advantech WebAccess version 9.1.3 that exposes sensitive information to unauthorized actors, potentially leading to the leakage of user credentials.
2
How severe is CVE-2023-4215?
CVE-2023-4215 has a severity rating of high with a CVSS score of 7.5.
3
What is affected by CVE-2023-4215?
Advantech WebAccess version 9.1.3 is affected by CVE-2023-4215.
4
What is the Common Weakness Enumeration (CWE) for CVE-2023-4215?
The CWE for CVE-2023-4215 is CWE-200.
5
How can I fix the CVE-2023-4215 vulnerability?
To fix the CVE-2023-4215 vulnerability, it is recommended to update Advantech WebAccess to a patched version or apply any security patches provided by the vendor.