peter bassill · operator
$ cve CVE-2018-15705 JSON

CVE-2018-15705 EXPLOIT

6.5
MEDIUM · CVSS 3.0 · EPSS 12.2% (pctl 96)

Patch early

A public exploit exists.

Description

WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code.

Scoring

CVSS6.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS12.24% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2018-10-31
Last modified2026-06-17

Affected (1)

VendorProduct
advantechwebaccess

Public exploits

SourceTitleDate
exploit-dbAdvantech WebAccess SCADA 8.3.2 - Remote Code Execution2018-11-05

References

→ the Explorer  ·  watch your stack  ·  NVD