Vulnerability index

Browse CVEs

360 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webaccess HIGH 7.8
CVE-2018-17908

WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the i…

Fix: after 8.3.2
Fix from $1,950 2018-10-29
Webaccess HIGH 7.8
CVE-2018-17910EPSS 5%

WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing a buffer overflow condition …

Fix: after 8.3.2
Fix from $1,950 2018-10-29
Webaccess CRITICAL 9.8
CVE-2018-14806

Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code.

Fix: after 8.3.1
Fix from $2,300 2018-10-23
Webaccess CRITICAL 9.8
CVE-2018-14816

Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified, which may allow an attacker …

Fix: after 8.3.1
Fix from $2,300 2018-10-23
Webaccess HIGH 7.8
CVE-2018-14828

Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perfo…

Fix: after 8.3.1
Fix from $1,950 2018-10-23
Webaccess HIGH 7.5
CVE-2018-14820

Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allo…

Fix: after 8.3.1
Fix from $1,950 2018-10-23
Webaccess HIGH 8.8
CVE-2018-15704EPSS 22%

Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit…

Fix: after 8.3.2
Fix from $1,950 2018-10-22
Webaccess MEDIUM 6.1
CVE-2018-15703

Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could…

Fix: after 8.3.2
Fix from $1,600 2018-10-22
Webaccess CRITICAL 9.8
CVE-2018-10589

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $2,300 2018-05-15
Webaccess CRITICAL 9.8
CVE-2018-7497

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $2,300 2018-05-15
Webaccess CRITICAL 9.8
CVE-2018-7499

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $2,300 2018-05-15
Webaccess CRITICAL 9.8
CVE-2018-7505

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $2,300 2018-05-15
Webaccess CRITICAL 9.8
CVE-2018-8845EPSS 6%

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $2,300 2018-05-15
Webaccess HIGH 7.8
CVE-2018-8841

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $1,950 2018-05-15
Webaccess HIGH 7.5
CVE-2018-10590

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $1,950 2018-05-15
Webaccess HIGH 7.5
CVE-2018-7495

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $1,950 2018-05-15
Webaccess HIGH 7.5
CVE-2018-7501

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $1,950 2018-05-15
Webaccess HIGH 7.5
CVE-2018-7503

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $1,950 2018-05-15
Webaccess MEDIUM 6.1
CVE-2018-10591

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $1,600 2018-05-15
Webaccess HIGH 7.8
CVE-2017-5175

Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within the search …

Fix: after 8.1
Fix from $1,950 2018-05-09
Webaccess Hmi Designer HIGH 7.8
CVE-2018-8833

Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files m…

Fix: after 2.1.7.32
Fix from $1,950 2018-04-25
Webaccess Hmi Designer HIGH 7.8
CVE-2018-8835

Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote…

Fix: after 2.1.7.32
Fix from $1,950 2018-04-25
Webaccess Hmi Designer HIGH 7.8
CVE-2018-8837

Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buf…

Fix: after 2.1.7.32
Fix from $1,950 2018-04-25
Webaccess CRITICAL 9.8
CVE-2018-6911EPSS 13%

The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argume…

No fix yet
Fix from $2,300 2018-02-13
Webaccess\/scada MEDIUM 5.3
CVE-2018-5443

A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does not properly sanitize its inp…

Fix: 8.2_20170817+
Fix from $1,600 2018-01-25
Webaccess\/scada MEDIUM 5.3
CVE-2018-5445

A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the d…

Fix: 8.2_20170817+
Fix from $1,600 2018-01-25
Webaccess HIGH 7.5
CVE-2017-16736

An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attac…

Fix: 8.3+
Fix from $1,950 2018-01-12
Webaccess MEDIUM 6.5
CVE-2017-16732

A use-after-free issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows an unauthenticated attacker to specify an arbitr…

Fix: 8.3+
Fix from $1,600 2018-01-12
Webaccess CRITICAL 9.8
CVE-2017-16716EPSS 6%

A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.

Fix: 8.3+
Fix from $2,300 2018-01-05
Webaccess CRITICAL 9.8
CVE-2017-16720EPSS 50%

A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the …

Fix: after 8.3.2
Fix from $2,300 2018-01-05