Show filters
37 Total Results
Displaying 11-20 of 37
Sort by:
Attacker Value
Unknown
CVE-2021-32956
Disclosure Date: June 18, 2021 (last updated February 22, 2025)
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage.
0
Attacker Value
Unknown
CVE-2021-22669
Disclosure Date: April 26, 2021 (last updated February 22, 2025)
Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, which may allow a low-privileged user to update an administrator’s password and login as an administrator to escalate privileges on the system.
0
Attacker Value
Unknown
CVE-2021-27436
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser actions.
0
Attacker Value
Unknown
CVE-2020-13554
Disclosure Date: March 03, 2021 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
0
Attacker Value
Unknown
CVE-2020-25161
Disclosure Date: February 23, 2021 (last updated February 22, 2025)
The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.
0
Attacker Value
Unknown
CVE-2020-13553
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
0
Attacker Value
Unknown
CVE-2020-13555
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
0
Attacker Value
Unknown
CVE-2020-13551
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
0
Attacker Value
Unknown
CVE-2020-13550
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-13552
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
0