10
CVSSv2

CVE-2018-6911

Published: 13/02/2018 Updated: 02/08/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote malicious users to execute arbitrary OS commands via a single argument (aka the command parameter).

Vulnerable Product Search on Vulmon Subscribe to Product

advantech webaccess 8.3.0

Exploits

Vulnerability Title: Advantech WebAccess Node830 "AspVBObjdll" - Remote Code Execution Discovered by: Nassim Asrir Contact: wassline@gmailcom / wwwlinkedincom/in/nassim-asrir-b73a57122/ CVE: CVE-2018-6911 Tested on: IE11 / Win10 Technical Details: ================== The VBWinExec function in Node\AspVBObjdll in Advantech WebA ...
Advantech WebAccess Node version 830 suffers from an AspVBObjdll code execution dll hijacking vulnerability ...