Authentication bypass in Advantech WebAccess - CVE-2017-5152
Published: January 12, 2017 / Updated: January 13, 2017
Advantech WebAccess
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to incorrectly imposed permissions to specific URL. A remote attacker can use a specially crafted URL to gain unauthorized access to Advantech WebAccess.
Successful exploitation will grant an attacker unauthorized access to web application.
How to mitigate CVE-2017-5152
http://www.advantech.com/industrial-automation/webaccess