Advantech WebAccess Flaws Allow Access to Sensitive Data

  • 13 January 2017
  • 0 replies
  • 128 views

Userlevel 7
Badge +54
By Eduard Kovacs on January 13, 2017
 
Advantech has patched a couple of serious vulnerabilities in WebAccess, a web-based software package for human-machine interfaces (HMI) and supervisory control and data acquisition (SCADA) systems.
 
The flaws, discovered by Tenable Network Security researchers and reported to the vendor via Trend Micro’s Zero Day Initiative (ZDI), allow a remote attacker to gain access to potentially sensitive information.
 
The vulnerabilities are tracked as CVE-2017-5154 and CVE-2017-5152, and they have been described as SQL injection and authentication bypass issues. ICS-CERT has assigned CVSS scores of 9.8 and 9.1, respectively, which puts them in the critical severity category.
 
Full Article

0 replies

Be the first to reply!

Reply