An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-24883 | An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users. |
Fixes
Solution
Advantech recommends users upgrade to v9.1.1 or later.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsa-21-285-01 |
|
History
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-16T18:28:58.187Z
Reserved: 2021-08-10T00:00:00.000Z
Link: CVE-2021-38431
No data.
Status : Modified
Published: 2021-10-15T13:15:07.533
Modified: 2024-11-21T06:17:05.020
Link: CVE-2021-38431
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD