RULE(RULE ID:321854)

Rule General Information
Release Date: 2019-06-14
Rule Name: Advantech WebAccess SCADA WADashboard readFile Directory Traversal Vulnerability (CVE-2018-15706)
Severity:
CVE ID:
Rule Protection Details
Description: WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: https://www.tenable.com/security/research/tra-2018-35
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.advantech.com.cn/