Skip to main content

Vendor/product archive

advantech / webaccess CVEs

Beta · best-effort

103 CVEs tagged to advantech / webaccess42 Critical, 46 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2017-5175

Published May 9, 2018

Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within the search path resulting in execution of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6911

Published Feb 13, 2018

The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-16736

Published Jan 12, 2018

An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attacker to upload arbitrary files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16732

Published Jan 12, 2018

A use-after-free issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows an unauthenticated attacker to specify an arbitrary address.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16753

Published Jan 5, 2018

An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows some inputs that may cause the program to crash.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16728

Published Jan 5, 2018

An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the prog…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-16724

Published Jan 5, 2018

A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple instances of a vulnerability that allows too much data to be wr…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-16720

Published Jan 5, 2018

A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-16716

Published Jan 5, 2018

A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-14016

Published Nov 6, 2017

A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied d…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-12719

Published Nov 6, 2017

An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A remote attacker is able to execute code to dereference a pointer wi…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-12717

Published Aug 30, 2017

An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A maliciously crafted dll file placed earlier in the search path m…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12713

Published Aug 30, 2017

An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files and folders with ACLs that aff…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12711

Published Aug 30, 2017

An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A built-in user account has been granted a sensitive privilege that…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12710

Published Aug 30, 2017

A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By submitting a specially crafted parameter, it is possible to inject arbitrary SQL st…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12708

Published Aug 30, 2017

An Improper Restriction Of Operations Within The Bounds Of A Memory Buffer issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 51-75 of 103 CVEsPage 3 of 5