#VU12751 Improper authorization in Advantech Co., Ltd products - CVE-2018-7505
Published: May 16, 2018
Advantech WebAccess
WebAccess Dashboard
WebAccess Scada Node
WebAccess/NMS
Advantech Co., Ltd
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in a TFTP application due to unrestricted file uploads to the web application without authorization. A remote attacker can bypass authorization and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.