CVE-2018-7505

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a TFTP application has unrestricted file uploads to the web application without authorization, which may allow an attacker to execute arbitrary code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
advantechwebaccess
𝑥
≤ 8.2_20170817
advantechwebaccess
𝑥
≤ 8.3.0
advantechwebaccess_dashboard
𝑥
≤ 2.0.15
advantechwebaccess_scada
𝑥
< 8.3.1
advantechwebaccess\/nms
𝑥
≤ 2.0.3
𝑥
= Vulnerable software versions