CVE-2019-10993
- EPSS 10.67%
- Veröffentlicht 28.06.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:20:18
In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute arbitrary code.
CVE-2019-3954
- EPSS 3.91%
- Veröffentlicht 19.06.2019 00:15:13
- Zuletzt bearbeitet 21.11.2024 04:42:56
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 81024 RPC call.
CVE-2019-3953
- EPSS 3.99%
- Veröffentlicht 18.06.2019 23:15:10
- Zuletzt bearbeitet 21.11.2024 04:42:56
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 10012 RPC call.
CVE-2019-3940
- EPSS 4.08%
- Veröffentlicht 09.04.2019 16:29:02
- Zuletzt bearbeitet 21.11.2024 04:42:54
Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.
CVE-2019-3941
- EPSS 2.39%
- Veröffentlicht 09.04.2019 16:29:02
- Zuletzt bearbeitet 21.11.2024 04:42:54
Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.
CVE-2019-6550
- EPSS 6.09%
- Veröffentlicht 05.04.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:40
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple stack-based buffer overflow vulnerabilities, caused by a lack of proper validation of the length of user-supplied data, may allow remote code execution.
CVE-2019-6552
- EPSS 3.27%
- Veröffentlicht 05.04.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:40
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplied data, may allow remote code execution.
CVE-2019-6554
- EPSS 1.57%
- Veröffentlicht 05.04.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:41
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service condition.
CVE-2018-15705
- EPSS 12.24%
- Veröffentlicht 31.10.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:18
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to r...
CVE-2018-15706
- EPSS 32.37%
- Veröffentlicht 31.10.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:18
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.