Filtered by vendor Advantech
Subscriptions
Filtered by product Webaccess
Subscriptions
Total
103 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2018-14828 | 1 Advantech | 1 Webaccess | 2023-11-07 | N/A |
Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perform actions at a system administrator level. | ||||
CVE-2018-14820 | 1 Advantech | 1 Webaccess | 2023-11-07 | N/A |
Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allow an arbitrary file deletion when processing. | ||||
CVE-2018-14816 | 1 Advantech | 1 Webaccess | 2023-11-07 | 9.8 Critical |
Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified, which may allow an attacker to execute arbitrary code. | ||||
CVE-2018-14806 | 1 Advantech | 1 Webaccess | 2023-11-07 | N/A |
Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code. | ||||
CVE-2023-4215 | 1 Advantech | 1 Webaccess | 2023-10-20 | 7.5 High |
Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials. | ||||
CVE-2023-2866 | 1 Advantech | 1 Webaccess | 2023-06-15 | 7.8 High |
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server. | ||||
CVE-2019-10983 | 1 Advantech | 1 Webaccess | 2023-03-24 | 7.5 High |
In WebAccess/SCADA Versions 8.3.5 and prior, an out-of-bounds read vulnerability is caused by a lack of proper validation of user-supplied data. Exploitation of this vulnerability may allow disclosure of information. | ||||
CVE-2019-10985 | 1 Advantech | 1 Webaccess | 2023-03-02 | 9.1 Critical |
In WebAccess/SCADA, Versions 8.3.5 and prior, a path traversal vulnerability is caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage this vulnerability to delete files while posing as an administrator. | ||||
CVE-2019-10987 | 1 Advantech | 1 Webaccess | 2023-03-02 | 8.8 High |
In WebAccess/SCADA Versions 8.3.5 and prior, multiple out-of-bounds write vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution. | ||||
CVE-2019-10989 | 1 Advantech | 1 Webaccess | 2023-03-02 | 9.8 Critical |
In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution. Note: A different vulnerability than CVE-2019-10991. | ||||
CVE-2019-10991 | 1 Advantech | 1 Webaccess | 2023-03-02 | 9.8 Critical |
In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution. | ||||
CVE-2019-10993 | 1 Advantech | 1 Webaccess | 2022-04-18 | 9.8 Critical |
In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute arbitrary code. | ||||
CVE-2020-10638 | 1 Advantech | 1 Webaccess | 2021-12-17 | 9.8 Critical |
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution. | ||||
CVE-2019-13552 | 1 Advantech | 1 Webaccess | 2021-10-28 | 8.8 High |
In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and may allow arbitrary file deletion and remote code execution. | ||||
CVE-2021-38389 | 1 Advantech | 1 Webaccess | 2021-10-20 | 9.8 Critical |
Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code. | ||||
CVE-2021-33023 | 1 Advantech | 1 Webaccess | 2021-10-20 | 9.8 Critical |
Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code. | ||||
CVE-2020-12002 | 1 Advantech | 1 Webaccess | 2021-09-23 | 9.8 Critical |
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution. | ||||
CVE-2020-12006 | 1 Advantech | 1 Webaccess | 2021-09-23 | 9.8 Critical |
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control. | ||||
CVE-2020-12010 | 1 Advantech | 1 Webaccess | 2021-09-23 | 7.1 High |
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control. | ||||
CVE-2020-12019 | 1 Advantech | 1 Webaccess | 2021-09-23 | 9.8 Critical |
WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code. |