Rewterz
Rewterz Threat Advisory – ICS: Schneider Electric IGSS
October 13, 2021
Rewterz
Rewterz Threat Advisory – ICS: Siemens SINEC NMS and SIMATIC
October 13, 2021

Rewterz Threat Advisory – ICS: Advantech WebAccess SCADA

Severity

Medium

Analysis Summary

CVE-2021-38431

An authenticated user can use API functions to disclose project names and paths from other users.

Impact

  • Unauthorized Access

Affected Vendors

  • Advantech

Affected Products

  • WebAccess/SCADA: Versions 9.0.3 and prior

Remediation

Refer to CERT-ICS Advisory for the patch, upgrade, or suggested workaround information.

https://us-cert.cisa.gov/ics/advisories/icsa-21-285-01