An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system and is encrypted with a static key hard-coded in the program. Attackers could reverse the admin account password for use.
📦
susiaccess
Vendor: advantech
Actively Exploited
0
CISA KEV List
PoC / Exploits
2
Code Available
Total RCEs
0
Remote Access
Total CVEs
54
Total Indexed
Avg. EPSS
4.24%
Exploit Prob.
Security Vulnerability Index
Page 1 / 6
7.8
CVSS
Severity: HIGH
7.0
CVSS
CVE-2016-9351
Exploit Found
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker to upload and unpack a zip file.
Severity: HIGH
7.5
CVSS
CVE-2016-9349
Exploit Found
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can result in information disclosure.
Severity: HIGH