Advantech WebAccess < 8.2_20170817 Multiple Vulnerabilities
Critical Nessus Plugin ID 103048
SynopsisThe remote host has a web application running that is affected by multiple vulnerabilities.
DescriptionThe Advantech WebAccess application running on the remote host is prior to version 8.2.2017.08.17. It is, therefore, affected by multiple vulnerabilities including SQL Injection, Out-of-Bounds Access, Multiple Buffer Overflows, Externally Controlled Format String, Improper Authentication, Incorrect Permission Assignment for Critical Resource, Incorrect Privilege Assignment, and Uncontrolled Search Path Element.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
SolutionUpgrade to Advantech WebAccess version V8.2_20170817 or later.