Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown
CVE-2024-2453
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.
0
Attacker Value
Unknown
CVE-2023-1437
Disclosure Date: August 02, 2023 (last updated October 11, 2023)
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.
0
Attacker Value
Unknown
CVE-2023-32628
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution.
0
Attacker Value
Unknown
CVE-2023-32540
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-22450
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2021-38431
Disclosure Date: October 12, 2021 (last updated February 23, 2025)
An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.
0
Attacker Value
Unknown
CVE-2021-22676
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection to a malicious webpage, and unintended browser action on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).
0
Attacker Value
Unknown
CVE-2021-32943
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).
0
Attacker Value
Unknown
CVE-2021-22674
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).
0
Attacker Value
Unknown
CVE-2021-32954
Disclosure Date: June 18, 2021 (last updated February 22, 2025)
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary files on the file system.
0