← Vulnerability feed

Vulnerability record · CVE-2017-16720 · published 5 January 2018

CVE-2017-16720: Advantech WebAccess path traversal exposes device files

Advantech · Webaccess

Advantech WebAccess versions 8.3.2 and earlier contain a path traversal flaw (CWE-22) that lets an attacker reach files within the target device's directory structure. The vulnerability is remotely reachable with no authentication or user interaction, and the record carries a critical CVSS 3.0 score of 9.8. It matters because WebAccess is an HMI/SCADA product, so exposed file access on a control-system host can lead to data disclosure and further compromise.

9.8 CVSS 3.0 Critical EPSS 50% · top 1.1% CWE-22 · Path traversal
9.8CVSS 3.0 base score, v2 10.0
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication, and a public exploit plus high EPSS probability make this a high-urgency issue for exposed WebAccess deployments.

What it is

Advantech WebAccess versions 8.3.2 and earlier contain a path traversal flaw (CWE-22) that lets an attacker reach files within the target device's directory structure. The vulnerability is remotely reachable with no authentication or user interaction, and the record carries a critical CVSS 3.0 score of 9.8. It matters because WebAccess is an HMI/SCADA product, so exposed file access on a control-system host can lead to data disclosure and further compromise.

Impact

An attacker gains read access to files on the target device, which can expose configuration, credential or project data used by the SCADA/HMI environment. The CVSS vector also rates integrity and availability impact as high, though the description only confirms file access.

Attack surface

The flaw is network-reachable (AV:N) with low complexity, no privileges and no user interaction (PR:N/UI:N), so any host that can reach the WebAccess service can attempt it. No authentication is required per the vector.

Exploitation

A public exploit exists in Exploit-DB (EDB-44278), and EPSS estimates a 30-day exploitation probability of about 0.50 (98.9th percentile). The CVE is not listed in CISA KEV, and no ransomware groups are documented as using it.

What to do

  • Upgrade Advantech WebAccess to a version later than 8.3.2; the record does not name a fixed release, so confirm with the vendor.
  • Restrict network access to the WebAccess service to trusted management hosts and block it from untrusted networks and the internet.
  • Run the WebAccess service with least privilege and isolate the host on a segmented control network.
  • Monitor the vendor and ICS-CERT advisory channels for updated guidance, since the referenced ICS-CERT advisory link is broken.

Detection

  • Inspect web server and application logs for traversal sequences such as ../ or encoded variants in request paths.
  • Alert on unexpected reads of files outside the WebAccess web root or project directories.
  • Baseline normal file access by the WebAccess process and flag deviations, especially reads of configuration or credential files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/102424 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-004-02 Broken LinkThird Party AdvisoryUS Government Resource
https://www.exploit-db.com/exploits/44278/ ExploitThird Party AdvisoryVDB Entry
https://www.tenable.com/security/research/tra-2018-23 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-18-024/ Third Party Advisory
http://www.securityfocus.com/bid/102424 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-004-02 Broken LinkThird Party AdvisoryUS Government Resource
https://www.exploit-db.com/exploits/44278/ ExploitThird Party AdvisoryVDB Entry
https://www.tenable.com/security/research/tra-2018-23 Third Party Advisory

Track CVE-2017-16720 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-9208Advantech webaccess memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code v…EPSS 9.3%9.8CVE-2021-33023Advantech webaccess heap-based buffer overflow vulnerabilityAdvantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.EPSS 2.3%9.8CVE-2021-38389Advantech webaccess stack-based buffer overflow vulnerabilityAdvantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.EPSS 10%9.8CVE-2021-38408Advantech webaccess stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of use…EPSS 12%9.8CVE-2020-12019Advantech webaccess stack-based buffer overflow vulnerabilityWebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.EPSS 2.2%9.8CVE-2020-10638Advantech webaccess heap-based buffer overflow vulnerabilityAdvantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities exist caused by a lack of prope…EPSS 7.1%9.8CVE-2020-12002Advantech webaccess stack-based buffer overflow vulnerabilityAdvantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of prop…EPSS 9.1%9.8CVE-2020-12006Advantech webaccess relative path traversal vulnerabilityAdvantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privile…EPSS 3.7%

Source: NIST National Vulnerability Database (record CVE-2017-16720), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.