Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.tenable.com/security/research/tra-2019-15 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: tenable
Published: 2020-04-01T16:04:29
Updated: 2024-08-04T19:26:27.802Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-3942
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-01T17:15:14.830
Modified: 2024-11-21T04:42:54.787
Link: CVE-2019-3942
Redhat
No data.