Show filters
325 Total Results
Displaying 41-50 of 325
Sort by:
Attacker Value
Unknown
CVE-2023-2866
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.
0
Attacker Value
Unknown
CVE-2023-32628
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution.
0
Attacker Value
Unknown
CVE-2023-32540
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-22450
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-2575
Disclosure Date: May 08, 2023 (last updated October 08, 2023)
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request.
0
Attacker Value
Unknown
CVE-2023-2574
Disclosure Date: May 08, 2023 (last updated February 14, 2025)
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.
0
Attacker Value
Unknown
CVE-2023-2573
Disclosure Date: May 08, 2023 (last updated February 14, 2025)
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.
0
Attacker Value
Unknown
CVE-2022-3386
Disclosure Date: October 27, 2022 (last updated November 08, 2023)
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.
0
Attacker Value
Unknown
CVE-2022-3385
Disclosure Date: October 27, 2022 (last updated November 08, 2023)
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.
0
Attacker Value
Unknown
CVE-2022-3387
Disclosure Date: October 27, 2022 (last updated November 08, 2023)
Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP code to delete .PDF files.
0