Show filters
211 Total Results
Displaying 31-40 of 211
Sort by:
Attacker Value
Unknown
CVE-2020-13551
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
0
Attacker Value
Unknown
CVE-2020-13550
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-13552
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
0
Attacker Value
Unknown
CVE-2020-16202
Disclosure Date: September 22, 2020 (last updated February 22, 2025)
WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system privileges.
0
Attacker Value
Unknown
CVE-2020-16229
Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a type confusion condition, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
0
Attacker Value
Unknown
CVE-2020-16217
Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by processing specially crafted project files may allow remote code execution, disclosure/modification of information, or cause the application to crash.
0
Attacker Value
Unknown
CVE-2020-16215
Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a stack-based buffer overflow, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
0
Attacker Value
Unknown
CVE-2020-16213
Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
0
Attacker Value
Unknown
CVE-2020-16211
Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by processing specially crafted project files, which may allow an attacker to read information.
0
Attacker Value
Unknown
CVE-2020-16207
Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by opening specially crafted project files that may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
0