Show filters
325 Total Results
Displaying 91-100 of 325
Sort by:
Attacker Value
Unknown

CVE-2021-38389

Disclosure Date: October 12, 2021 (last updated February 23, 2025)
Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.
Attacker Value
Unknown

CVE-2021-33023

Disclosure Date: October 12, 2021 (last updated February 23, 2025)
Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.
Attacker Value
Unknown

CVE-2021-38431

Disclosure Date: October 12, 2021 (last updated February 23, 2025)
An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.
Attacker Value
Unknown

CVE-2021-38408

Disclosure Date: September 09, 2021 (last updated February 23, 2025)
A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.
Attacker Value
Unknown

CVE-2021-32951

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources monitored and controlled by the WebAccess/NMS, as well as IP addresses and names of all the devices managed via WebAccess/NMS.
Attacker Value
Unknown

CVE-2021-22676

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection to a malicious webpage, and unintended browser action on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).
Attacker Value
Unknown

CVE-2021-32943

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).
Attacker Value
Unknown

CVE-2021-22674

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).
Attacker Value
Unknown

CVE-2021-21805

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary OS command execution. An attacker can send a crafted HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-21804

Disclosure Date: July 16, 2021 (last updated February 23, 2025)
A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary PHP code execution. An attacker can send a crafted HTTP request to trigger this vulnerability.