Advantech / Webaccess
103 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-4215 | Advantech WebAccess Debug Messages Revealing Unnecessary Information | HIGH | 7.5 | Oct 16, 2023 |
| CVE-2023-2866 | Advantech WebAccess Insufficient Type Distinction | HIGH | 7.8 | Jun 7, 2023 |
| CVE-2021-38389 | Advantech WebAccess | CRITICAL | 9.8 | Oct 18, 2021 |
| CVE-2021-33023 | Advantech WebAccess | CRITICAL | 9.8 | Oct 18, 2021 |
| CVE-2021-38408 | A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user-supplied… | CRITICAL | 9.8 | Sep 9, 2021 |
| CVE-2021-34540 | Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard. | MEDIUM | 6.1 | Jun 11, 2021 |
| CVE-2020-16202 | WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system… | HIGH | 7.8 | Sep 22, 2020 |
| CVE-2020-12019 | WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code. | CRITICAL | 9.8 | Jun 15, 2020 |
| CVE-2020-12018 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exists that may allow access to unauthorized data. | HIGH | 7.5 | May 8, 2020 |
| CVE-2020-12002 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validat… | CRITICAL | 9.8 | May 8, 2020 |
| CVE-2020-10638 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities exist caused by a lack of proper validati… | CRITICAL | 9.8 | May 8, 2020 |
| CVE-2020-12026 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to… | HIGH | 8.8 | May 8, 2020 |
| CVE-2020-12014 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized and may allow an attacker to inject SQL commands. | HIGH | 7.5 | May 8, 2020 |
| CVE-2020-12006 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to… | CRITICAL | 9.8 | May 8, 2020 |
| CVE-2020-12010 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user t… | HIGH | 7.1 | May 8, 2020 |
| CVE-2020-12022 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An improper validation vulnerability exists that could allow an attacker to inject specially… | CRITICAL | 9.8 | May 8, 2020 |
| CVE-2019-3942 | Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerabilit… | HIGH | 7.5 | Apr 1, 2020 |
| CVE-2020-10607 | In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper validation of the length of user-suppl… | HIGH | 8.8 | Mar 27, 2020 |
| CVE-2019-3951 | Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (memory corruption) due to a st… | CRITICAL | 9.8 | Dec 12, 2019 |
| CVE-2019-13558 | In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote code execu… | CRITICAL | 9.8 | Sep 18, 2019 |
| CVE-2019-13556 | In WebAccess versions 8.4.1 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-sup… | HIGH | 8.8 | Sep 18, 2019 |
| CVE-2019-13552 | In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and may allow… | HIGH | 8.8 | Sep 18, 2019 |
| CVE-2019-13550 | In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improper control… | CRITICAL | 9.8 | Sep 18, 2019 |
| CVE-2019-3975 | Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbitrary code via a crafted IOCTL 70603 RP… | CRITICAL | 9.8 | Sep 10, 2019 |
| CVE-2019-10993 | In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute arbitrary code. | CRITICAL | 9.8 | Jun 28, 2019 |
Showing 1 to 25 of 103 CVEs