In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2023-06-05T23:16:28.045Z
Updated: 2024-08-02T15:18:37.624Z
Reserved: 2023-05-22T18:07:54.491Z
Link: CVE-2023-32540
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-06-06T00:15:10.067
Modified: 2024-11-21T08:03:33.563
Link: CVE-2023-32540
Redhat
No data.