CVE-2020-16202

HIGH

Advantech Webaccess < 9.0.1 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system privileges.

References (1)

Core 1
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-20-261-01

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 8.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
advantech/webaccess < 9.0.1
Published Sep 22, 2020
Tracked Since Feb 18, 2026