You are here

Advantech WebAccess/SCADA (ICSA-20-289-01) – Product Used in the Water and Wastewater and Energy Sectors

Advantech WebAccess/SCADA (ICSA-20-289-01) – Product Used in the Water and Wastewater and Energy Sectors

Created: Thursday, October 15, 2020 - 13:44
Categories:
Cybersecurity

CISA has published an advisory on an external control of file name or path vulnerability in Advantech WebAccess/SCADA. Versions 9.0 and prior are affected. Successful exploitation of this vulnerability could allow an attacker to execute remote code as an administrator. Advantech recommends users update to Version 9.0.1 or later. CISA also recommends a series of measures to mitigate the vulnerability. Read the advisory at CISA.