CVE-2021-32951
- EPSS 0.13%
- Veröffentlicht 27.10.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:59
WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources monitored and controlled by the WebAccess/NMS, as well as IP addresses and names of all the devices ...
CVE-2020-10631
- EPSS 0.26%
- Veröffentlicht 09.04.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:44
An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
CVE-2020-10629
- EPSS 0.16%
- Veröffentlicht 09.04.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:43
WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files.
CVE-2020-10625
- EPSS 0.25%
- Veröffentlicht 09.04.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:43
WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account.
CVE-2020-10623
- EPSS 0.14%
- Veröffentlicht 09.04.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:43
Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to gain access to sensitive information.
CVE-2020-10619
- EPSS 1.86%
- Veröffentlicht 09.04.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:42
An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
CVE-2020-10617
- EPSS 0.28%
- Veröffentlicht 09.04.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:42
There are multiple ways an unauthenticated attacker could perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to gain access to sensitive information.
CVE-2020-10603
- EPSS 0.39%
- Veröffentlicht 09.04.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:40
WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.
- EPSS 0.22%
- Veröffentlicht 09.04.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:42
Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).
CVE-2018-8845
- EPSS 1.52%
- Veröffentlicht 15.05.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:26
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a heap-based buffer overfl...