In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-152-01 | Mitigation Third Party Advisory US Government Resource | 
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-152-01 | Mitigation Third Party Advisory US Government Resource | 
Configurations
                    History
                    No history.
Information
                Published : 2023-06-06 00:15
Updated : 2024-11-21 08:03
NVD link : CVE-2023-32540
Mitre link : CVE-2023-32540
CVE.ORG link : CVE-2023-32540
JSON object : View
Products Affected
                advantech
- webaccess\/scada
CWE
                
                    
                        
                        CWE-94
                        
            Improper Control of Generation of Code ('Code Injection')
