Advantech Updates
2449Warning Date
Severity Level
Warning Number
Target Sector
13 October, 2021
● Critical
2021-3661
Energy - Water and Utilities - Manufacturing
Description:
Advantech has released security updates to address several vulnerabilities in the following products:
- WebAccess, an HMI platform
- WebAccess Versions 9.02 and prior
- WebAccess/SCADA, an HMI platform
- WebAccess/SCADA: Versions 9.0.3 and prior
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Remote code execution
Best practice and Recommendations:
The CERT team encourages users to review Microsoft security advisory and apply the necessary updates:
Best practices:
- Minimizing network exposure for all control system devices and/or systems
- Locating control system networks and devices behind firewalls and isolating them from the enterprise/business network
- When remote access is required, use secure methods such as virtual private networks (VPNs)