Vulnerability Description
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via a full pathname in an argument to the sub_401A90 CreateFileW function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advantech | Advantech Studio | 6.1 |
| Indusoft | Web Studio | 6.1 |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/pdf/ICSA-13-067-01.pdf
- http://ics-cert.us-cert.gov/pdf/ICSA-13-067-01.pdf
FAQ
What is CVE-2013-1627?
CVE-2013-1627 is a vulnerability with a CVSS score of 7.8 (HIGH). Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via a full pathname in ...
How severe is CVE-2013-1627?
CVE-2013-1627 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-1627?
Check the references section above for vendor advisories and patch information. Affected products include: Advantech Advantech Studio, Indusoft Web Studio.