Show filters
325 Total Results
Displaying 41-50 of 325
Sort by:
Attacker Value
Unknown

CVE-2023-2866

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.
Attacker Value
Unknown

CVE-2023-32628

Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution.
Attacker Value
Unknown

CVE-2023-32540

Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2023-22450

Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2023-2575

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request.
Attacker Value
Unknown

CVE-2023-2574

Disclosure Date: May 08, 2023 (last updated February 14, 2025)
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.
Attacker Value
Unknown

CVE-2023-2573

Disclosure Date: May 08, 2023 (last updated February 14, 2025)
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.
Attacker Value
Unknown

CVE-2022-3386

Disclosure Date: October 27, 2022 (last updated November 08, 2023)
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.
Attacker Value
Unknown

CVE-2022-3385

Disclosure Date: October 27, 2022 (last updated November 08, 2023)
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.
Attacker Value
Unknown

CVE-2022-3387

Disclosure Date: October 27, 2022 (last updated November 08, 2023)
Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP code to delete .PDF files.