CVE-2016-9351
Advantech SUSIAccess Server UpgradeMgmt upload Directory Traversal Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker to upload and unpack a zip file.
Ha sido descubierto un problema en Advantech SUISAccess Server versiĆ³n 3.0 y anteriores. El error de subida de directorio transversal/file permite a un atacante cargar y descomprimir un archivo zip.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Advantech SUSIAccess Server. Authentication is required to exploit this vulnerability.
The specific flaw exists within the processing of the UpgradeMgmt servlet upload function. The issue lies in the failure to properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute arbitrary code under the context of SYSTEM.
Advantech SUSIAccess versions 3.0 and below suffers from a RecoveryMgmt file upload vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-11-16 CVE Reserved
- 2016-12-13 CVE Published
- 2024-05-16 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/94629 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-16-336-04 | Mitigation |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/42402 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Advantech Search vendor "Advantech" | Susiaccess Search vendor "Advantech" for product "Susiaccess" | <= 3.0 Search vendor "Advantech" for product "Susiaccess" and version " <= 3.0" | - |
Affected
|