Vulnerability index

Browse CVEs

89 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Webaccess CRITICAL 9.8
CVE-2019-3975

Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbitrary code via a crafted IOCT…

No fix yet
Fix from $2,300 2019-09-10
Webaccess CRITICAL 9.8
CVE-2019-3954

Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a craft…

No fix yet
Fix from $2,300 2019-06-19
Webaccess CRITICAL 9.8
CVE-2019-3953

Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a craft…

No fix yet
Fix from $2,300 2019-06-18
Webaccess CRITICAL 9.8
CVE-2019-3940

Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnera…

Mitigation only
Fix from $2,300 2019-04-09
Webaccess HIGH 7.5
CVE-2019-3941

Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.

No fix yet
Fix from $1,950 2019-04-09
Webaccess\/scada CRITICAL 9.8
CVE-2019-6519

WebAccess/SCADA, Version 8.3. An improper authentication vulnerability exists that could allow a possible authentication bypass allowing an attacker …

Mitigation only
Fix from $2,300 2019-02-05
Webaccess\/scada CRITICAL 9.8
CVE-2019-6523

WebAccess/SCADA, Version 8.3. The software does not properly sanitize its inputs for SQL commands.

Mitigation only
Fix from $2,300 2019-02-05
Webaccess\/scada HIGH 8.6
CVE-2019-6521

WebAccess/SCADA, Version 8.3. Specially crafted requests could allow a possible authentication bypass that could allow an attacker to obtain and mani…

Mitigation only
Fix from $1,950 2019-02-05
Webaccess\/scada HIGH 7.3
CVE-2018-18999

WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user supplied input may allow an attack…

Mitigation only
Fix from $1,950 2018-12-19
Webaccess MEDIUM 6.5
CVE-2018-15705EPSS 12%

WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to …

No fix yet
Fix from $1,600 2018-10-31
Webaccess MEDIUM 6.5
CVE-2018-15706EPSS 32%

WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory tr…

No fix yet
Fix from $1,600 2018-10-31
Webaccess MEDIUM 5.4
CVE-2018-15707

Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability …

No fix yet
Fix from $1,600 2018-10-31
Webaccess CRITICAL 9.8
CVE-2018-6911EPSS 13%

The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argume…

No fix yet
Fix from $2,300 2018-02-13
Webop HIGH 7.8
CVE-2017-12705

A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to trigger a heap-based buffer o…

Mitigation only
Fix from $1,950 2017-10-25
Webaccess CRITICAL 9.8
CVE-2017-5154

An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed …

Mitigation only
Fix from $2,300 2017-02-13
Webaccess CRITICAL 9.1
CVE-2017-5152

An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious use…

Mitigation only
Fix from $2,300 2017-02-13
Vesp211 Eu Firmware CRITICAL 9.8
CVE-2016-2275

The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on t…

Mitigation only
Fix from $2,300 2016-02-21
Webaccess MEDIUM 6.9
CVE-2014-9202

Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_20150816 allow remote attackers to execute arbitra…

Mitigation only
Fix from $1,600 2015-09-28
Eki 6340 Firmware HIGH 9.0
CVE-2014-8387EPSS 31%

cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metachar…

No fix yet
Fix from $1,950 2014-11-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0987

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeNa…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0988

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the Access…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0989

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the Access…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0990

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the UserNa…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0991

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the projec…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0992

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the passwo…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0985

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeNa…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Webaccess MEDIUM 6.8
CVE-2014-0986

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the GotoCm…

Mitigation only
Fix from $1,600 2014-09-20
Advantech Studio HIGH 7.8
CVE-2013-1627

Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attack…

Mitigation only
Fix from $1,950 2013-03-11
Adam 6015 HIGH 10.0
CVE-2008-5848

The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP sess…

Mitigation only
Fix from $1,950 2009-01-06