Advantech WebAccess Unpatched RCE

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# Advantech WebAccess Unpatched RCE ## Author: Chris Lyne ### Summary [Tenable Research](https://www.tenable.com/security/research/tra-2018-23) has discovered that Advantech WebAccess remains unprotected against a public exploit several months after a patch was said to be released. Vulnerable WebAccess instances are susceptible to an unauthenticated remote code execution attack. This post discusses the vulnerability and relevant events in great detail. ### Background On January 4th, 2018 ICS-CERT released [ICSA-18–004–02A](https://ics-cert.us-cert.gov/advisories/ICSA-18-004-02A) to detail several vulnerabilities reported for Advantech WebAccess. One of the vulnerabilities, [CVE-2017–16720](https://nvd.nist.gov/vuln/detail/CVE-2017-16720), which was also [disclosed](https://www.zerodayinitiative.com/advisories/ZDI-18-024/) by the Zero Day Initiative (ZDI), allows an unauthenticated remote attacker to execute arbitrary system commands. The mitigation section of the ICS-CERT advisory...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息