Show filters
211 Total Results
Displaying 1-10 of 211
Sort by:
Attacker Value
Unknown

Advantech WebAccess Webvrpcs Service Opcode 80061 Stack Buffer Overflow

Disclosure Date: November 06, 2017 (last updated October 05, 2023)
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.
0
Attacker Value
Unknown

CVE-2024-2453

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.
0
Attacker Value
Unknown

CVE-2023-4215

Disclosure Date: October 17, 2023 (last updated October 21, 2023)
Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.
Attacker Value
Unknown

CVE-2023-1437

Disclosure Date: August 02, 2023 (last updated October 11, 2023)
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.
Attacker Value
Unknown

CVE-2023-2866

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.
Attacker Value
Unknown

CVE-2023-32628

Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution.
Attacker Value
Unknown

CVE-2023-32540

Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2023-22450

Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2021-42703

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser action.
Attacker Value
Unknown

CVE-2021-42706

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
This vulnerability could allow an attacker to disclose information and execute arbitrary code on affected installations of WebAccess/MHI Designer