Show filters
325 Total Results
Displaying 31-40 of 325
Sort by:
Attacker Value
Unknown

CVE-2024-28948

Disclosure Date: September 27, 2024 (last updated October 05, 2024)
Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.
Attacker Value
Unknown

CVE-2024-2453

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.
0
Attacker Value
Unknown

CVE-2023-5642

Disclosure Date: October 18, 2023 (last updated October 25, 2023)
Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information.
Attacker Value
Unknown

CVE-2023-4215

Disclosure Date: October 17, 2023 (last updated October 21, 2023)
Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.
Attacker Value
Unknown

CVE-2023-4203

Disclosure Date: August 08, 2023 (last updated February 14, 2025)
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface.
Attacker Value
Unknown

CVE-2023-4202

Disclosure Date: August 08, 2023 (last updated February 14, 2025)
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.
Attacker Value
Unknown

CVE-2023-1437

Disclosure Date: August 02, 2023 (last updated October 11, 2023)
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.
Attacker Value
Unknown

CVE-2023-3983

Disclosure Date: July 31, 2023 (last updated October 08, 2023)
An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.
Attacker Value
Unknown

CVE-2023-3256

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.
Attacker Value
Unknown

CVE-2023-2611

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users.