ID

VAR-201904-0333


CVE

CVE-2019-3940


TITLE

Advantech WebAccess Code Issue Vulnerability

Trust: 0.8

sources: IVD: ed3f090d-7f3e-4836-870e-acc7e4660ef3 // CNVD: CNVD-2019-32474

DESCRIPTION

Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code. Advantech WebAccess Contains a vulnerability related to unlimited uploads of dangerous types of files.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Advantech WebAccess is a browser-based HMI/SCADA software from Advantech, Taiwan. The software supports dynamic graphical display and real-time data control, and provides the ability to remotely control and manage automation equipment. Advantech WebAccess is prone to the following security vulnerabilities: 1. An arbitrary file-download vulnerability 2. This may aid in further attacks. Advantech WebAccess 8.3.4 is vulnerable; other versions may also be affected. This vulnerability stems from improper design or implementation problems in the code development process of network systems or products

Trust: 2.79

sources: NVD: CVE-2019-3940 // JVNDB: JVNDB-2019-003313 // CNVD: CNVD-2019-32474 // BID: 107847 // IVD: ed3f090d-7f3e-4836-870e-acc7e4660ef3 // VULHUB: VHN-155375 // VULMON: CVE-2019-3940

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: ed3f090d-7f3e-4836-870e-acc7e4660ef3 // CNVD: CNVD-2019-32474

AFFECTED PRODUCTS

vendor:advantechmodel:webaccessscope:eqversion:8.3.4

Trust: 2.4

vendor:advantechmodel:webaccess/scadascope:eqversion:8.3.4

Trust: 0.3

vendor:advantechmodel:webaccess/scadascope:neversion:8.3.5

Trust: 0.3

vendor:webaccessmodel: - scope:eqversion:8.3.4

Trust: 0.2

sources: IVD: ed3f090d-7f3e-4836-870e-acc7e4660ef3 // CNVD: CNVD-2019-32474 // BID: 107847 // JVNDB: JVNDB-2019-003313 // NVD: CVE-2019-3940

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-3940
value: CRITICAL

Trust: 1.0

NVD: CVE-2019-3940
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2019-32474
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201904-485
value: CRITICAL

Trust: 0.6

IVD: ed3f090d-7f3e-4836-870e-acc7e4660ef3
value: CRITICAL

Trust: 0.2

VULHUB: VHN-155375
value: HIGH

Trust: 0.1

VULMON: CVE-2019-3940
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-3940
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2019-32474
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: ed3f090d-7f3e-4836-870e-acc7e4660ef3
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-155375
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-3940
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: IVD: ed3f090d-7f3e-4836-870e-acc7e4660ef3 // CNVD: CNVD-2019-32474 // VULHUB: VHN-155375 // VULMON: CVE-2019-3940 // JVNDB: JVNDB-2019-003313 // CNNVD: CNNVD-201904-485 // NVD: CVE-2019-3940

PROBLEMTYPE DATA

problemtype:CWE-434

Trust: 1.9

sources: VULHUB: VHN-155375 // JVNDB: JVNDB-2019-003313 // NVD: CVE-2019-3940

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201904-485

TYPE

Code problem

Trust: 0.8

sources: IVD: ed3f090d-7f3e-4836-870e-acc7e4660ef3 // CNNVD: CNNVD-201904-485

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-003313

PATCH

title:Advantech WebAccessurl:https://www.advantech.co.jp/industrial-automation/webaccess

Trust: 0.8

title:Patch for Advantech WebAccess Code Issue Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/181481

Trust: 0.6

title:Advantech WebAccess Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=91310

Trust: 0.6

sources: CNVD: CNVD-2019-32474 // JVNDB: JVNDB-2019-003313 // CNNVD: CNNVD-201904-485

EXTERNAL IDS

db:NVDid:CVE-2019-3940

Trust: 3.7

db:TENABLEid:TRA-2019-15

Trust: 3.5

db:BIDid:107847

Trust: 2.1

db:CNNVDid:CNNVD-201904-485

Trust: 0.9

db:CNVDid:CNVD-2019-32474

Trust: 0.8

db:JVNDBid:JVNDB-2019-003313

Trust: 0.8

db:IVDid:ED3F090D-7F3E-4836-870E-ACC7E4660EF3

Trust: 0.2

db:VULHUBid:VHN-155375

Trust: 0.1

db:VULMONid:CVE-2019-3940

Trust: 0.1

sources: IVD: ed3f090d-7f3e-4836-870e-acc7e4660ef3 // CNVD: CNVD-2019-32474 // VULHUB: VHN-155375 // VULMON: CVE-2019-3940 // BID: 107847 // JVNDB: JVNDB-2019-003313 // CNNVD: CNNVD-201904-485 // NVD: CVE-2019-3940

REFERENCES

url:https://www.tenable.com/security/research/tra-2019-15

Trust: 3.5

url:http://www.securityfocus.com/bid/107847

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2019-3940

Trust: 1.4

url:http://webaccess.advantech.com

Trust: 0.9

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-3940

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/434.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2019-32474 // VULHUB: VHN-155375 // VULMON: CVE-2019-3940 // BID: 107847 // JVNDB: JVNDB-2019-003313 // CNNVD: CNNVD-201904-485 // NVD: CVE-2019-3940

CREDITS

Tenable

Trust: 0.9

sources: BID: 107847 // CNNVD: CNNVD-201904-485

SOURCES

db:IVDid:ed3f090d-7f3e-4836-870e-acc7e4660ef3
db:CNVDid:CNVD-2019-32474
db:VULHUBid:VHN-155375
db:VULMONid:CVE-2019-3940
db:BIDid:107847
db:JVNDBid:JVNDB-2019-003313
db:CNNVDid:CNNVD-201904-485
db:NVDid:CVE-2019-3940

LAST UPDATE DATE

2024-08-14T15:12:25.098000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-32474date:2019-09-21T00:00:00
db:VULHUBid:VHN-155375date:2019-10-09T00:00:00
db:VULMONid:CVE-2019-3940date:2019-10-09T00:00:00
db:BIDid:107847date:2019-04-03T00:00:00
db:JVNDBid:JVNDB-2019-003313date:2019-05-14T00:00:00
db:CNNVDid:CNNVD-201904-485date:2019-04-19T00:00:00
db:NVDid:CVE-2019-3940date:2019-10-09T23:49:57.900

SOURCES RELEASE DATE

db:IVDid:ed3f090d-7f3e-4836-870e-acc7e4660ef3date:2019-09-21T00:00:00
db:CNVDid:CNVD-2019-32474date:2019-09-21T00:00:00
db:VULHUBid:VHN-155375date:2019-04-09T00:00:00
db:VULMONid:CVE-2019-3940date:2019-04-09T00:00:00
db:BIDid:107847date:2019-04-03T00:00:00
db:JVNDBid:JVNDB-2019-003313date:2019-05-14T00:00:00
db:CNNVDid:CNNVD-201904-485date:2019-04-09T00:00:00
db:NVDid:CVE-2019-3940date:2019-04-09T16:29:02.100