CVE-2019-3942

HIGH

Advantech WebAccess 8.3.4 - Unauthenticated Arbitrary File Read via RPC

Title source: llm
STIX 2.1

Description

Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.tenable.com/security/research/tra-2019-15

Scores

CVSS v3 7.5
EPSS 0.0094
EPSS Percentile 76.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-284 CWE-522
Status published
Products (1)
advantech/webaccess 8.3.4
Published Apr 01, 2020
Tracked Since Feb 18, 2026