In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-152-01 | Mitigation Third Party Advisory US Government Resource |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: icscert
Published: 2023-06-05T23:16:28.045Z
Updated: 2023-06-05T23:16:28.045Z
Reserved: 2023-05-22T18:07:54.491Z
Link: CVE-2023-32540
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-06-06T00:15:10.067
Modified: 2023-06-12T16:55:37.857
Link: CVE-2023-32540
JSON object: View
Redhat Information
No data.
CWE