Show filters
211 Total Results
Displaying 81-90 of 211
Sort by:
Attacker Value
Unknown
CVE-2019-6550
Disclosure Date: April 05, 2019 (last updated November 27, 2024)
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple stack-based buffer overflow vulnerabilities, caused by a lack of proper validation of the length of user-supplied data, may allow remote code execution.
0
Attacker Value
Unknown
CVE-2019-6554
Disclosure Date: April 05, 2019 (last updated November 27, 2024)
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service condition.
0
Attacker Value
Unknown
CVE-2019-6552
Disclosure Date: April 05, 2019 (last updated November 27, 2024)
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplied data, may allow remote code execution.
0
Attacker Value
Unknown
CVE-2019-6519
Disclosure Date: February 05, 2019 (last updated November 27, 2024)
WebAccess/SCADA, Version 8.3. An improper authentication vulnerability exists that could allow a possible authentication bypass allowing an attacker to upload malicious data.
0
Attacker Value
Unknown
CVE-2019-6521
Disclosure Date: February 05, 2019 (last updated November 27, 2024)
WebAccess/SCADA, Version 8.3. Specially crafted requests could allow a possible authentication bypass that could allow an attacker to obtain and manipulate sensitive information.
0
Attacker Value
Unknown
CVE-2019-6523
Disclosure Date: February 05, 2019 (last updated November 27, 2024)
WebAccess/SCADA, Version 8.3. The software does not properly sanitize its inputs for SQL commands.
0
Attacker Value
Unknown
CVE-2018-18999
Disclosure Date: December 19, 2018 (last updated November 27, 2024)
WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user supplied input may allow an attacker to cause the overflow of a buffer on the stack.
0
Attacker Value
Unknown
CVE-2018-15705
Disclosure Date: October 31, 2018 (last updated November 27, 2024)
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code.
0
Attacker Value
Unknown
CVE-2018-15707
Disclosure Date: October 31, 2018 (last updated November 27, 2024)
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.
0
Attacker Value
Unknown
CVE-2018-15706
Disclosure Date: October 31, 2018 (last updated November 27, 2024)
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.
0