Advantech WebAccess/SCADA
Advantech WebAccess/SCADA versions 8.4.5 contain a privilege escalation or improper access control vulnerability in the WebAccess Dashboard component (WADashboardSetup.msi and associated files). Successful exploitation allows an attacker with local access to gain full control over the SCADA server. The vulnerability is not remotely exploitable. Advantech has released version 9.1.4 which removes the vulnerable files. For version 8.4.5, the workaround is to uninstall the WebAccess Dashboard component and delete the associated files.
- Local access to the WebAccess/SCADA server
- WebAccess/SCADA version 8.4.5 with WADashboard component installed
- Ability to interact with the vulnerable component (user-level or low-privilege account sufficient)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/465add38-0e12-415e-ac46-7b0096298a75Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.