Vulnerability index

Browse CVEs

360 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50369

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50367

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50368

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50365

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50366

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50362

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50363

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50364

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50360

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50361

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 2g Firmware HIGH 7.2
CVE-2024-50359

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices …

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Eki 6333ac 1gpo Firmware HIGH 7.2
CVE-2024-50358

A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2…

Fix: 1.2.2 / 1.6.5+
Fix from $1,950 2024-11-26
Iview HIGH 7.5
CVE-2023-52335

Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensi…

Fix: 5.7.04.6752+
Fix from $1,950 2024-11-22
Adam 5630 Firmware HIGH 8.8
CVE-2024-39275

Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cooki…

Fix: 2.5.2+
Fix from $1,950 2024-09-27
Adam 5630 Firmware HIGH 8.8
CVE-2024-28948

Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, w…

Fix: 2.5.2+
Fix from $1,950 2024-09-27
Adam 5550 Firmware MEDIUM 6.1
CVE-2024-38308

Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't cor…

Mitigation only
Fix from $1,600 2024-09-27
Adam 5630 Firmware MEDIUM 5.7
CVE-2024-34542

Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.

Fix: 2.5.2+
Fix from $1,600 2024-09-27
Adam 5550 Firmware MEDIUM 5.7
CVE-2024-37187

Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.

Mitigation only
Fix from $1,600 2024-09-27
R Seenet CRITICAL 9.8
CVE-2023-5642EPSS 17%

Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive informa…

No fix yet
Fix from $2,300 2023-10-18
Webaccess HIGH 7.5
CVE-2023-4215

Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentia…

No fix yet
Fix from $1,950 2023-10-17
Eki 1524 Firmware MEDIUM 5.4
CVE-2023-4203

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by au…

Fix: after 1.24
Fix from $1,600 2023-08-08
Eki 1524 Firmware MEDIUM 5.4
CVE-2023-4202

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by au…

Fix: after 1.21
Fix from $1,600 2023-08-08
Webaccess\/scada CRITICAL 9.8
CVE-2023-1437

All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain…

Fix: 9.1.4+
Fix from $2,300 2023-08-02
Iview HIGH 8.8
CVE-2023-3983EPSS 17%

An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypa…

Fix: 5.7.4.6752+
Fix from $1,950 2023-07-31
R Seenet CRITICAL 9.8
CVE-2023-2611

Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a pas…

Fix: after 2.4.22
Fix from $2,300 2023-06-22
R Seenet HIGH 8.1
CVE-2023-3256

Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.

Fix: after 2.4.22
Fix from $1,950 2023-06-22
Webaccess HIGH 7.8
CVE-2023-2866

If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could…

Mitigation only
Fix from $1,950 2023-06-07
Webaccess\/scada CRITICAL 9.8
CVE-2023-32540

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file…

Fix: after 9.1.3
Fix from $2,300 2023-06-06
Webaccess\/scada CRITICAL 9.8
CVE-2023-32628

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extensi…

Fix: after 9.1.3
Fix from $2,300 2023-06-06
Webaccess\/scada HIGH 7.2
CVE-2023-22450

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script fi…

Fix: after 9.1.3
Fix from $1,950 2023-06-06