CVE-2017-12717

HIGH

Advantech Webaccess < 8.2 - Uncontrolled Search Path

Title source: rule

Description

An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A maliciously crafted dll file placed earlier in the search path may allow an attacker to execute code within the context of the application.

Scores

CVSS v3 7.8
EPSS 0.0067
EPSS Percentile 71.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status draft

Affected Products (1)

advantech/webaccess < 8.2

Timeline

Published Aug 30, 2017
Tracked Since Feb 18, 2026