CVE-2020-16202

HIGH

Advantech WebAccess < 9.0.1 - Incorrect Permission Assignment for Critical Resource

Title source: llm
STIX 2.1

Description

WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system privileges.

References (1)

Core 1
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-20-261-01

Scores

CVSS v3 7.8
EPSS 0.0038
EPSS Percentile 29.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
advantech/webaccess < 9.0.1
Published Sep 22, 2020
Tracked Since Feb 18, 2026