HTTP: Advantech WebAccess Node chkLogin2 SQL Injection

An SQL injection vulnerability has been reported in Advantech WebAccess Node. The vulnerability is due to insufficient validation of input used to construct SQL queries. Successful exploitation could allow the attacker to access and modify potentially sensitive information.

Extended Description

A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands.

Affected Products

Advantech webaccess/scada

Short Name
HTTP:SQL:INJ:WEBACCESS-SQL
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Advantech CVE-2018-5443 Injection Node SQL WebAccess chkLogin2
Release Date
11/27/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Advantech

CVSS Score

5.0

Found a potential security threat?