nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-10621 CVE-2020-10621
CRITICAL
advantech webaccess\/nms Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2020-10621 has a selected CVSS score of 9.8 (critical).
Description
Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 27, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
webaccess\/nmsBrowse advantech / webaccess\/nms | VulnCheck | Version data not supplied | |
WebAccess/NMS | CVE List | Versions prior to 3.0.2 | affected |
References
2us-cert.gov
https://www.us-cert.gov/ics/advisories/icsa-20-098-01