RULE(RULE ID:712846)

Rule General Information
Release Date: 2019-06-14
Rule Name: Advantech WebAccess Directory Traversal Vulnerability (CVE-2017-16720)
Severity:
CVE ID:
Rule Protection Details
Description: A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:102424
ExploitDB:44278
https://ics-cert.us-cert.gov/advisories/ICSA-18-004-02
https://www.tenable.com/security/research/tra-2018-23
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.advantech.com/