CVE-2025-14850

8.1

Advantech · WebAccess/SCADA

Advantech WebAccess/SCADA contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files on the host system.

Executive summary

A directory traversal flaw in Advantech WebAccess/SCADA version 9.2.1 poses a significant risk to system integrity by allowing unauthorized file deletion.

Vulnerability

The application is susceptible to a directory traversal vulnerability (CWE-22) that permits an authenticated user to traverse outside intended directories to delete arbitrary files on the underlying file system. Based on the CVSS vector (PR:L), this attack requires the user to have low-level privileges to interact with the vulnerable function.

Business impact

Successful exploitation of this vulnerability could lead to the deletion of critical configuration, system, or application files, resulting in severe operational disruption or loss of availability for SCADA systems. With a CVSS score of 8.1, the high impact on file integrity and availability necessitates immediate attention, particularly in industrial control environments where uptime is critical.

Remediation

Immediate Action: Update Advantech WebAccess/SCADA to version 9.2.2 or later as specified in the vendor advisory.

Proactive Monitoring: Monitor system logs for unusual file deletion activity or unauthorized attempts to access directories outside of the application's defined scope.

Compensating Controls: Restrict access to the WebAccess/SCADA interface to trusted internal networks only, and ensure that the service account running the application operates with the least privilege necessary to perform its functions.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical role of SCADA systems in industrial operations, the risk posed by unauthorized file deletion is severe. Security teams should prioritize the update to version 9.2.2 to eliminate the underlying path traversal flaw. If patching is not immediately feasible, ensure strict network segmentation and identity controls are in place to prevent low-privileged users from accessing the vulnerable interface.

More Advantech CVEs

Sources

Originally found and disclosed by Alex Wiliams from Pellera Technologies reported these vulnerabilities to CISA., per the CVE Program record.