CVE-2016-9349 EXPLOIT
7.5
HIGH · CVSS 3.0 · EPSS 7.9% (pctl 95)
Patch early
A public exploit exists.
Description
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can result in information disclosure.
Scoring
| CVSS | 7.5 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 7.88% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-02-13 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| advantech | susiaccess |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Advantech SUSIAccess < 3.0 - Directory Traversal / Information Disclosure (Metasploit) | 2017-08-01 |
| exploit-db | Advantech SUSIAccess < 3.0 - 'RecoveryMgmt' File Upload | 2017-08-01 |
References
- http://www.securityfocus.com/bid/94629
- https://ics-cert.us-cert.gov/advisories/ICSA-16-336-04
- https://www.exploit-db.com/exploits/42401/
- https://www.exploit-db.com/exploits/42402/
- http://www.securityfocus.com/bid/94629
- https://ics-cert.us-cert.gov/advisories/ICSA-16-336-04
- https://www.exploit-db.com/exploits/42401/
- https://www.exploit-db.com/exploits/42402/
→ the Explorer · watch your stack · NVD