Arbitrary file upload in WebAccess/SCADA - CVE-2019-3940
Published: September 19, 2019
WebAccess/SCADA
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to the "webvrpcs.exe" accepts unauthenticated RPC calls to perform remote file operations including fopen, fseek, ftell, fread, fwrite and fclose. A remote attacker can send a specially crafted RPC call to the application, upload and execute arbitrary file on the system.