Show filters
325 Total Results
Displaying 111-120 of 325
Sort by:
Attacker Value
Unknown
CVE-2021-32932
Disclosure Date: June 11, 2021 (last updated February 22, 2025)
The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182).
0
Attacker Value
Unknown
CVE-2021-32930
Disclosure Date: June 11, 2021 (last updated February 22, 2025)
The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arbitrary code on the iView (versions prior to v5.7.03.6182).
0
Attacker Value
Unknown
CVE-2021-34540
Disclosure Date: June 11, 2021 (last updated February 22, 2025)
Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.
0
Attacker Value
Unknown
CVE-2021-27437
Disclosure Date: May 07, 2021 (last updated February 22, 2025)
The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).
0
Attacker Value
Unknown
CVE-2021-22669
Disclosure Date: April 26, 2021 (last updated February 22, 2025)
Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, which may allow a low-privileged user to update an administrator’s password and login as an administrator to escalate privileges on the system.
0
Attacker Value
Unknown
CVE-2021-27436
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser actions.
0
Attacker Value
Unknown
CVE-2019-18231
Disclosure Date: March 17, 2021 (last updated February 22, 2025)
Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.
0
Attacker Value
Unknown
CVE-2019-18233
Disclosure Date: March 17, 2021 (last updated February 22, 2025)
In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack.
0
Attacker Value
Unknown
CVE-2019-18235
Disclosure Date: March 17, 2021 (last updated February 22, 2025)
Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack.
0
Attacker Value
Unknown
CVE-2020-13554
Disclosure Date: March 03, 2021 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
0