HTTP: Advantech WebAccess SCADA WADashboard readFile Directory Traversal

This signature detects attempts to exploit a known vulnerability against Advantech WebAccess SCADA WADashboard. Successful exploitation could lead to the disclosure of information.

Extended Description

WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.

Affected Products

Advantech webaccess

Short Name
HTTP:DIR:CVE-2018-15706-IN-DIS
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Advantech CVE-2018-15706 Directory SCADA Traversal WADashboard WebAccess readFile
Release Date
11/27/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Advantech

CVSS Score

6.8

Found a potential security threat?