All versions prior to 9.1.4 of Advantech WebAccess/SCADA...
Critical severity
Unreviewed
Published
Aug 3, 2023
to the GitHub Advisory Database
•
Updated Feb 9, 2024
Description
Published by the National Vulnerability Database
Aug 2, 2023
Published to the GitHub Advisory Database
Aug 3, 2023
Last updated
Feb 9, 2024
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent client could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.
References