Vulnerability Description
An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unrestricted (AUTHENTICATION BYPASS).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advantech | Webaccess | 8.1 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/95410Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-012-01MitigationThird Party AdvisoryUS Government Resource
- https://www.tenable.com/security/research/tra-2017-04
- http://www.securityfocus.com/bid/95410Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-012-01MitigationThird Party AdvisoryUS Government Resource
- https://www.tenable.com/security/research/tra-2017-04
FAQ
What is CVE-2017-5152?
CVE-2017-5152 is a vulnerability with a CVSS score of 9.1 (CRITICAL). An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unrestricted (AUTHENTICAT...
How severe is CVE-2017-5152?
CVE-2017-5152 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-5152?
Check the references section above for vendor advisories and patch information. Affected products include: Advantech Webaccess.