HTTP: Advantech WebAccess SCADA Cross-Site Scripting

A cross-site scripting vulnerability has been reported in Advantech WebAccess. This vulnerability is due to insufficient sanitization of user-supplied input to the web application. Successful exploitation could result in the execution of script code in security context of the target user's browser.

Extended Description

Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.

Affected Products

Advantech webaccess

Short Name
HTTP:XSS:WEBACCESS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Advantech CVE-2018-15707 Cross-Site SCADA Scripting WebAccess
Release Date
11/20/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Advantech

CVSS Score

3.5

Found a potential security threat?