Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Advantech WebAccess Insufficient Type Distinction
Vulnerability Description
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
不充分的类型区分
Vulnerability Title
Advantech WebAccess/SCADA 数据伪造问题漏洞
Vulnerability Description
Advantech WebAccess/SCADA是中国研华(Advantech)公司的一套基于浏览器架构的SCADA软件。该软件支持动态图形显示和实时数据控制,并提供远程控制和管理自动化设备的功能。 Advantech WebAccess/SCADA 8.4.5版本存在安全漏洞。攻击者利用该漏洞可以完全控制监控和数据采集 (SCADA) 服务器。
CVSS Information
N/A
Vulnerability Type
N/A