← back
CVE-2020-13552

CVE-2020-13552

CVSS 8.8 HIGHEPSS 0.5%CWE-276
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
17 Feb 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
n/a · Advantech

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →