7.8

CVE-2023-2866

Advantech WebAccess Insufficient Type Distinction

If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server. 

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Advantech ≫ Webaccess Version 8.4.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.041
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
DHS.gov 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

CWE-351 Insufficient Type Distinction

The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.

https://www.cisa.gov/news-events/ics-advisories/icsa-23-150-01
Third Party Advisory
US Government Resource