Advantech

Webaccess/scada

25 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Published 21.03.2024 23:15:11
  • Last modified 21.11.2024 09:09:47

There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify ...

  • EPSS 0.11%
  • Published 02.08.2023 23:15:10
  • Last modified 21.11.2024 07:39:11

All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the ...

  • EPSS 0.22%
  • Published 06.06.2023 00:15:10
  • Last modified 21.11.2024 08:03:44

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution. ...

  • EPSS 0.09%
  • Published 06.06.2023 00:15:10
  • Last modified 21.11.2024 08:03:33

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file...

  • EPSS 0.09%
  • Published 06.06.2023 00:15:09
  • Last modified 21.11.2024 07:44:49

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.

  • EPSS 0.86%
  • Published 10.08.2021 15:15:07
  • Last modified 21.11.2024 06:07:58

The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).

  • EPSS 0.19%
  • Published 10.08.2021 15:15:07
  • Last modified 21.11.2024 05:50:27

UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection to a malicious webpage, and uni...

  • EPSS 0.31%
  • Published 10.08.2021 14:15:07
  • Last modified 21.11.2024 05:50:27

The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0...

  • EPSS 0.16%
  • Published 18.06.2021 14:15:08
  • Last modified 21.11.2024 06:08:00

Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage.

  • EPSS 0.21%
  • Published 18.06.2021 14:15:08
  • Last modified 21.11.2024 06:07:59

Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary files on the file system.