CVE-2023-2866
07.06.2023, 21:15
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.Enginsight
Vendor | Product | Version |
---|---|---|
advantech | webaccess | 8.4.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-351 - Insufficient Type DistinctionThe software does not properly distinguish between different types of elements in a way that leads to insecure behavior.
- CWE-345 - Insufficient Verification of Data AuthenticityThe software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.