In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-36784 | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution. |
Fixes
Solution
Advantech recommends WebAccess/SCADA users upgrade to v9.1.4 https://www.advantech.com/en/support/details/installation .
Workaround
No workaround given by the vendor.
References
History
Wed, 08 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-08T14:22:14.896Z
Reserved: 2023-05-22T18:07:54.491Z
Link: CVE-2023-32540
Updated: 2024-08-02T15:18:37.624Z
Status : Modified
Published: 2023-06-06T00:15:10.067
Modified: 2024-11-21T08:03:33.563
Link: CVE-2023-32540
No data.
OpenCVE Enrichment
No data.
EUVD