Skip to main content

Vendor/product archive

advantech / webaccess CVEs

Beta · best-effort

103 CVEs tagged to advantech / webaccess42 Critical, 46 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2017-12706

Published Aug 30, 2017

A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a la…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12704

Published Aug 30, 2017

A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12702

Published Aug 30, 2017

An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. String format specifiers based on user provided input are not p…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12698

Published Aug 30, 2017

An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible authentication bypass that coul…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7929

Published May 6, 2017

An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an att…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5810

Published May 2, 2017

upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5154

Published Feb 13, 2017

An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess softwar…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-5152

Published Feb 13, 2017

An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unre…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4528

Published Jun 25, 2016

Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file.

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4525

Published Jun 25, 2016

Unspecified ActiveX controls in Advantech WebAccess before 8.1_20160519 allow remote authenticated users to obtain sensitive information or modify data via unknown vectors, relate…

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-0860

Published Jan 15, 2016

Buffer overflow in the BwpAlarm subsystem in Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service via a crafted RPC request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0859

Published Jan 15, 2016

Integer overflow in the Kernel service in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-0858

Published Jan 15, 2016

Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted request.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0857

Published Jan 15, 2016

Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-0856

Published Jan 15, 2016

Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
23.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2016-0855

Published Jan 15, 2016

Directory traversal vulnerability in Advantech WebAccess before 8.1 allows remote attackers to list arbitrary virtual-directory files via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0854

Published Jan 15, 2016

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-0853

Published Jan 15, 2016

Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted input.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0852

Published Jan 15, 2016

Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirement and obtain file or folder access via unspecified vectors.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-0851

Published Jan 15, 2016

Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service (out-of-bounds memory access) via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6467

Published Jan 15, 2016

Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3948

Published Jan 15, 2016

Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3947

Published Jan 15, 2016

SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3946

Published Jan 15, 2016

Cross-site request forgery (CSRF) vulnerability in Advantech WebAccess before 8.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3943

Published Jan 15, 2016

Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 103 CVEsPage 4 of 5