VYPR
Unrated severityNVD Advisory· Published May 15, 2018· Updated Sep 17, 2024

CVE-2018-7495

CVE-2018-7495

Description

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an external control of file name or path vulnerability has been identified, which may allow an attacker to delete files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An external control of file name or path vulnerability in Advantech WebAccess products allows remote attackers to delete arbitrary files.

Vulnerability

An external control of file name or path vulnerability exists in Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior [1]. The vulnerability is listed as CWE-73: External Control of File Name or Path. The affected software fails to properly sanitize user input used to construct file paths, allowing an attacker to control which file is targeted for deletion.

Exploitation

An attacker can exploit this vulnerability remotely without authentication and with low skill level [1]. The attacker sends a specially crafted request to the affected web application, manipulating the file name or path parameter to point to an arbitrary file on the system. No user interaction is required beyond the attacker crafting the malicious request. The vulnerability is network-exploitable via the HTTP/HTTPS interface.

Impact

Successful exploitation of this vulnerability allows an attacker to delete arbitrary files from the host system [1]. Depending on which files are deleted, this could lead to a denial of service, data loss, or potentially assist in further compromise of the system. The CVSS v3 base score is 9.8 (Critical) with the vector string AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating high impact on confidentiality, integrity, and availability [1].

Mitigation

Advantech has released updates to address this vulnerability [1]. Users should upgrade to the following versions or later: WebAccess 8.3.1, WebAccess Dashboard 2.0.16, WebAccess Scada Node 8.3.1, and WebAccess/NMS 2.0.4. The advisory also recommends that users minimize network exposure and ensure the software is not accessible from untrusted networks. This vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • Range: <8.3.1
  • Range: <=V2.0.15
  • Advantech/Webaccessllm-fuzzy2 versions
    <=V8.3.0+ 1 more
    • (no CPE)range: <=V8.3.0
    • (no CPE)range: WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, WebAccess/NMS 2.0.3 and prior.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.