Show filters
211 Total Results
Displaying 41-50 of 211
Sort by:
Attacker Value
Unknown

CVE-2020-12019

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
Attacker Value
Unknown

CVE-2020-12026

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.
Attacker Value
Unknown

CVE-2020-12006

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.
Attacker Value
Unknown

CVE-2020-10638

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.
Attacker Value
Unknown

CVE-2020-12022

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An improper validation vulnerability exists that could allow an attacker to inject specially crafted input into memory where it can be executed.
Attacker Value
Unknown

CVE-2020-12010

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control.
Attacker Value
Unknown

CVE-2020-12018

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exists that may allow access to unauthorized data.
Attacker Value
Unknown

CVE-2020-12002

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.
Attacker Value
Unknown

CVE-2020-12014

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized and may allow an attacker to inject SQL commands.
Attacker Value
Unknown

CVE-2020-10623

Disclosure Date: April 09, 2020 (last updated February 21, 2025)
Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to gain access to sensitive information.