RULE(RULE ID:332443)

Rule General Information
Release Date: 2021-01-28
Rule Name: Advantech WebAccess NMS Directory Traversal Vulnerability (CVE-2020-10619)
Severity:
CVE ID:
Rule Protection Details
Description: An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux
Reference: https://www.us-cert.gov/ics/advisories/icsa-20-098-01
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.advantech.com/