HTTP: Advantech WebAccess SCADA picfile Arbitrary File Upload

An arbitrary file upload vulnerability exists in Advantech WebAccess SCADA software. Successful exploitation could lead to arbitrary code execution on the target application with privileges of the web application process.

Extended Description

An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attacker to upload arbitrary files.

Affected Products

Advantech webaccess

Short Name
HTTP:DIR:ADVANTECH-DIR-TR
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Advantech Arbitrary CVE-2017-16736 File SCADA Upload WebAccess picfile
Release Date
03/13/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Advantech

CVSS Score

5.0

Found a potential security threat?