Incorrect default permissions in WebAccess/SCADA - CVE-2020-13552
Published: February 17, 2021
WebAccess/SCADA
Advantech Co., Ltd
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions within the "WebAccessMongoDB", "SaaS-Composer_keep-alive", "Dashboard", "WISE-PaaS_SaaS-Composer" and "InfluxDB" executables. A local user with access to the system can view contents of files and directories or modify them.