Advantech WISE-PaaS RMM UpgradeMgmt upload_ota Arbitrary File Upload

Strike ID:
G21-7phr1
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
0
Year:
2019

Description

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an administrator.

CVE

Metasploit

Zdi