CVE-2021-22669
CVE-2021-22669
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
26 Apr 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, which may allow a low-privileged user to update an administrator’s password and login as an administrator to escalate privileges on the system.
Affected products
n/a · Advantech WebAccess/SCADAWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →