Vulnerable WebAccess instances are susceptible to an unauthenticated remote code execution attack. ICS-CERT released ICSA-1800402A to detail several vulnerabilities reported for Advantech WebAccess. In March, a public exploit leveraging CVE-201716720 was published to the Exploit Database. In July, Tenable discovered that WebAccess version 8.3 is affected by this vulnerability. The vulnerability allows for remote command execution via the Remote Procedure Call (RPC) protocol over TCP port 4592.”]
Source: https://medium.com/tenable-techblog/advantech-webaccess-unpatched-rce-ffe9f37f8b83