CVE-2019-3942

Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.
Configurations

Configuration 1 (hide)

cpe:2.3:a:advantech:webaccess:8.3.4:*:*:*:*:*:*:*

History

21 Nov 2024, 04:42

Type Values Removed Values Added
References () https://www.tenable.com/security/research/tra-2019-15 - Third Party Advisory () https://www.tenable.com/security/research/tra-2019-15 - Third Party Advisory

Information

Published : 2020-04-01 17:15

Updated : 2024-11-21 04:42


NVD link : CVE-2019-3942

Mitre link : CVE-2019-3942

CVE.ORG link : CVE-2019-3942


JSON object : View

Products Affected

advantech

  • webaccess
CWE
CWE-284

Improper Access Control

CWE-522

Insufficiently Protected Credentials