CVE-2019-3942

Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.
References
Link Resource
https://www.tenable.com/security/research/tra-2019-15 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:advantech:webaccess:8.3.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-04-01 17:15

Updated : 2023-12-10 13:27


NVD link : CVE-2019-3942

Mitre link : CVE-2019-3942

CVE.ORG link : CVE-2019-3942


JSON object : View

Products Affected

advantech

  • webaccess
CWE
CWE-522

Insufficiently Protected Credentials

CWE-284

Improper Access Control