107847vdb entry
http://www.securityfocus.com/bid/107847 CVE-2019-3940
CRITICAL
Record summary
CVE-2019-3940 has a selected CVSS score of 9.8 (critical).
Description
Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WebAccessBrowse Advantech / WebAccess | CVE List | 8.3.4 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-3940 tenable.com
https://www.tenable.com/security/research/tra-2019-15