Vulnerability index

Browse CVEs

89 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-3975 Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbitrary code via a crafted IOCT… Webaccess No fix yet Fix from $2,3002019-09-10 CRITICAL 9.8 CVE-2019-3954 Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a craft… Webaccess No fix yet Fix from $2,3002019-06-19 CRITICAL 9.8 CVE-2019-3953 Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a craft… Webaccess No fix yet Fix from $2,3002019-06-18 CRITICAL 9.8 CVE-2019-3940 Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnera… Webaccess Mitigation only Fix from $2,3002019-04-09 HIGH 7.5 CVE-2019-3941 Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC. Webaccess No fix yet Fix from $1,9502019-04-09 CRITICAL 9.8 CVE-2019-6519 WebAccess/SCADA, Version 8.3. An improper authentication vulnerability exists that could allow a possible authentication bypass allowing an attacker … Webaccess\/scada Mitigation only Fix from $2,3002019-02-05 CRITICAL 9.8 CVE-2019-6523 WebAccess/SCADA, Version 8.3. The software does not properly sanitize its inputs for SQL commands. Webaccess\/scada Mitigation only Fix from $2,3002019-02-05 HIGH 8.6 CVE-2019-6521 WebAccess/SCADA, Version 8.3. Specially crafted requests could allow a possible authentication bypass that could allow an attacker to obtain and mani… Webaccess\/scada Mitigation only Fix from $1,9502019-02-05 HIGH 7.3 CVE-2018-18999 WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user supplied input may allow an attack… Webaccess\/scada Mitigation only Fix from $1,9502018-12-19 MEDIUM 6.5 CVE-2018-15705EPSS 12% WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to … Webaccess No fix yet Fix from $1,6002018-10-31 MEDIUM 6.5 CVE-2018-15706EPSS 32% WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory tr… Webaccess No fix yet Fix from $1,6002018-10-31 MEDIUM 5.4 CVE-2018-15707 Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability … Webaccess No fix yet Fix from $1,6002018-10-31 CRITICAL 9.8 CVE-2018-6911EPSS 13% The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argume… Webaccess No fix yet Fix from $2,3002018-02-13 HIGH 7.8 CVE-2017-12705 A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to trigger a heap-based buffer o… Webop Mitigation only Fix from $1,9502017-10-25 CRITICAL 9.8 CVE-2017-5154 An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed … Webaccess Mitigation only Fix from $2,3002017-02-13 CRITICAL 9.1 CVE-2017-5152 An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious use… Webaccess Mitigation only Fix from $2,3002017-02-13 CRITICAL 9.8 CVE-2016-2275 The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on t… Vesp211 Eu Firmware Mitigation only Fix from $2,3002016-02-21 MEDIUM 6.9 CVE-2014-9202 Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_20150816 allow remote attackers to execute arbitra… Webaccess Mitigation only Fix from $1,6002015-09-28 HIGH 9.0 CVE-2014-8387EPSS 31% cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metachar… Eki 6340 Firmware No fix yet Fix from $1,9502014-11-20 MEDIUM 6.8 CVE-2014-0987 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeNa… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0988 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the Access… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0989 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the Access… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0990 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the UserNa… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0991 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the projec… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0992 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the passwo… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0985 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeNa… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 MEDIUM 6.8 CVE-2014-0986 Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the GotoCm… Advantech Webaccess Mitigation only Fix from $1,6002014-09-20 HIGH 7.8 CVE-2013-1627 Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attack… Advantech Studio Mitigation only Fix from $1,9502013-03-11 HIGH 10.0 CVE-2008-5848 The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP sess… Adam 6015 Mitigation only Fix from $1,9502009-01-06