Lucene search

K
zdiSivathmican SivakumaranZDI-20-1261
HistoryOct 19, 2020 - 12:00 a.m.

Advantech WebAccess/SCADA WADashboard External Control of File Path Remote Code Execution Vulnerability

2020-10-1900:00:00
Sivathmican Sivakumaran
www.zerodayinitiative.com
21

0.002 Low

EPSS

Percentile

60.2%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Advantech WebAccess/SCADA. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the WADashboard component. The issue results from the lack of proper validation of a user-supplied path prior to using it to read and execute code from a file. An attacker can leverage this vulnerability to execute code in the context of Administrator.

0.002 Low

EPSS

Percentile

60.2%

Related for ZDI-20-1261