CVE-2017-16720 is a critical path traversal vulnerability affecting Advantech WebAccess versions 8.3.2 and earlier, allowing an unauthenticated attacker to access arbitrary files within the target device's directory structure. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, public exploit code exists on ExploitDB, and it has garnered some community discussion and media coverage, indicating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.3.2CPE matchmatch criteria | cpe:2.3:a:advantech:webaccess:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Advantech WebAccess Remote Code Execution
Sep 10, 2018[R1] Advantech WebAccess Remote Code Execution
Sep 10, 2018Advantech WebAccess Remote Code Execution
Sep 10, 2018[R1] Advantech WebAccess Remote Code Execution
Sep 10, 2018