Release date:
Updated on:
Affected Systems:
Advantech BroadWin WebAccess 7.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52051
Cve id: CVE-2011-4521, CVE-2011-4522, CVE-2011-4523, CVE-2011-4524, CVE-2011-4525, CVE-2011-4526, CVE-2012-0233, CVE-2012-0234, CVE-2012-0235, CVE-2012-0236, CVE-2012-0237, CVE-2012-0238, CVE-2012-0239, CVE-2012-0240, CVE-2012-0244, CVE-2012-0243
BroadWin SCADA WebAccess is a Web browser-based HMI and SCADA software for industrial control systems and automation.
Advantech WebAccess has multiple remote vulnerabilities. Attackers can exploit these vulnerabilities to steal Cookie authentication creden。, control applications, access or modify data, execute arbitrary code, and cause DOS.
<* Source: Prabhu S Angadi
Link: http://www.us-cert.gov/control_systems/pdf/ICSA-11-279-01.pdf
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Advantech
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://webaccess.advantech.com/product.php