7
CVSSv3

CVE-2016-9351

Published: 13/02/2017 Updated: 12/08/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an malicious user to upload and unpack a zip file.

Vulnerable Product Search on Vulmon Subscribe to Product

advantech susiaccess

Exploits

#! /usr/bin/env ruby =begin Exploit Title: Advantech SUSIAccess RecoveryMgmt File Upload Date: 07/31/17 Exploit Author: james fitts Vendor Homepage: wwwadvantechcom/ Version: Advantech SUSIAccess <= 30 Tested on: Windows 7 SP1 Relavant Advisories: ZDI-16-630 ZDI-16-628 CVE-2016-9349 CVE-2016-9351 BID-94629 ICSA-16-336-04 Notes ...
Advantech SUSIAccess versions 30 and below suffers from a RecoveryMgmt file upload vulnerability ...