In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin validation error vulnerability has been identified, which may allow an attacker can create a malicious web site, steal session cookies, and access data of authenticated users.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-2663 In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin validation error vulnerability has been identified, which may allow an attacker can create a malicious web site, steal session cookies, and access data of authenticated users.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-09-16T18:19:27.437Z

Reserved: 2018-05-01T00:00:00

Link: CVE-2018-10591

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-15T22:29:00.363

Modified: 2024-11-21T03:41:37.217

Link: CVE-2018-10591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.