Vulnerability index

Browse CVEs

360 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Iview HIGH 7.5
CVE-2021-32932

The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior …

Fix: 5.7.03.6182+
Fix from $1,950 2021-06-11
Iview CRITICAL 9.8
CVE-2021-32930EPSS 8%

The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute ar…

Fix: 5.7.03.6182+
Fix from $2,300 2021-06-11
Webaccess MEDIUM 6.1
CVE-2021-34540

Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.

No fix yet
Fix from $1,600 2021-06-11
Wise Paas\/rmm CRITICAL 9.1
CVE-2021-27437

The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator us…

Fix: 9.0.1+
Fix from $2,300 2021-05-07
Webaccess\/scada HIGH 8.8
CVE-2021-22669

Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, whic…

Fix: after 9.0.1
Fix from $1,950 2021-04-26
Webaccess\/scada MEDIUM 6.1
CVE-2021-27436

WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an uns…

Fix: after 9.0
Fix from $1,600 2021-03-18
Spectre Rt Ert351 Firmware CRITICAL 9.8
CVE-2019-18235

Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an a…

Fix: after 5.1.3
Fix from $2,300 2021-03-17
Spectre Rt Ert351 Firmware HIGH 7.5
CVE-2019-18231

Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercep…

Fix: after 5.1.3
Fix from $1,950 2021-03-17
Spectre Rt Ert351 Firmware MEDIUM 6.1
CVE-2019-18233

In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response,…

Fix: after 5.1.3
Fix from $1,600 2021-03-17
Webaccess\/scada HIGH 7.8
CVE-2020-13554

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webv…

No fix yet
Fix from $1,950 2021-03-03
Bb Eswgp506 2sfp T Firmware CRITICAL 9.8
CVE-2021-22667

BB-ESWGP506-2SFP-T versions 1.01.09 and prior is vulnerable due to the use of hard-coded credentials, which may allow an attacker to gain unauthorize…

Fix: after 1.01.09
Fix from $2,300 2021-02-24
Webaccess\/scada HIGH 8.8
CVE-2020-25161

The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the …

Fix: 9.0.1+
Fix from $1,950 2021-02-23
Webaccess\/scada HIGH 8.8
CVE-2020-13551

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In priv…

No fix yet
Fix from $1,950 2021-02-17
Webaccess\/scada HIGH 8.8
CVE-2020-13552

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In priv…

No fix yet
Fix from $1,950 2021-02-17
Webaccess\/scada HIGH 8.8
CVE-2020-13553

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webv…

No fix yet
Fix from $1,950 2021-02-17
Webaccess\/scada HIGH 8.8
CVE-2020-13555

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM …

No fix yet
Fix from $1,950 2021-02-17
Webaccess\/scada HIGH 7.7
CVE-2020-13550

A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can…

No fix yet
Fix from $1,950 2021-02-17
Iview CRITICAL 9.8
CVE-2021-22652EPSS 37%

Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to ch…

Fix: 5.7.03.6112+
Fix from $2,300 2021-02-11
Iview CRITICAL 9.8
CVE-2021-22658EPSS 13%

Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrato…

Fix: 5.7.03.6112+
Fix from $2,300 2021-02-11
Iview HIGH 7.5
CVE-2021-22654EPSS 12%

Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information.

Fix: 5.7.03.6112+
Fix from $1,950 2021-02-11
Iview HIGH 7.5
CVE-2021-22656

Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files.

Fix: 5.7.03.6112+
Fix from $1,950 2021-02-11
R Seenet HIGH 7.5
CVE-2020-25157

The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve…

Fix: after 2.4.10
Fix from $1,950 2020-10-20
Webaccess HIGH 7.8
CVE-2020-16202

WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution wi…

Fix: 9.0.1+
Fix from $1,950 2020-09-22
Iview CRITICAL 9.8
CVE-2020-16245EPSS 8%

Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/…

Fix: after 5.7
Fix from $2,300 2020-08-25
Webaccess\/hmi Designer HIGH 7.8
CVE-2020-16207

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by opening specia…

Fix: after 2.1.9.31
Fix from $1,950 2020-08-06
Webaccess\/hmi Designer HIGH 7.8
CVE-2020-16213

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied …

Fix: after 2.1.9.31
Fix from $1,950 2020-08-06
Webaccess\/hmi Designer HIGH 7.8
CVE-2020-16215

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied …

Fix: after 2.1.9.31
Fix from $1,950 2020-08-06
Webaccess\/hmi Designer HIGH 7.8
CVE-2020-16217

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by processing specially crafted project files may a…

Fix: after 2.1.9.31
Fix from $1,950 2020-08-06
Webaccess\/hmi Designer HIGH 7.8
CVE-2020-16229

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied …

Fix: after 2.1.9.31
Fix from $1,950 2020-08-06
Webaccess\/hmi Designer MEDIUM 5.5
CVE-2020-16211

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by processing specially crafted p…

Fix: after 2.1.9.31
Fix from $1,600 2020-08-06