Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-54089 Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.
Fixes

Solution

Advantech recommends users update WebAccess to Version 9.1.4 https://www.advantech.com/en/support/details/installation


Workaround

No workaround given by the vendor.

History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Oct 2024 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 24 Oct 2024 16:45:00 +0000

Type Values Removed Values Added
Title Advantech WebAccess Exposure of Sensitive Information to an Unauthorized Actor Advantech WebAccess Debug Messages Revealing Unnecessary Information
Weaknesses CWE-1295

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:29:28.472Z

Reserved: 2023-08-07T19:13:54.357Z

Link: CVE-2023-4215

cve-icon Vulnrichment

Updated: 2024-08-02T07:17:12.201Z

cve-icon NVD

Status : Modified

Published: 2023-10-17T00:15:11.327

Modified: 2024-11-21T08:34:38.370

Link: CVE-2023-4215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.