Vulnerabilities
Vulnerable Software
Advantech:  Security Vulnerabilities
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.
CVSS Score
6.5
EPSS Score
0.044
Published
2018-10-31
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.
CVSS Score
5.4
EPSS Score
0.011
Published
2018-10-31
WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the installation is complete. This could allow an attacker to run elevated arbitrary code.
CVSS Score
7.8
EPSS Score
0.001
Published
2018-10-29
WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing a buffer overflow condition that allows for arbitrary remote code execution.
CVSS Score
7.8
EPSS Score
0.031
Published
2018-10-29
Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code.
CVSS Score
9.8
EPSS Score
0.116
Published
2018-10-23
Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified, which may allow an attacker to execute arbitrary code.
CVSS Score
9.8
EPSS Score
0.041
Published
2018-10-23
Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allow an arbitrary file deletion when processing.
CVSS Score
7.5
EPSS Score
0.013
Published
2018-10-23
Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perform actions at a system administrator level.
CVSS Score
7.8
EPSS Score
0.001
Published
2018-10-23
Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply malicious HTML or JavaScript code to WebAccess, which is then reflected back to the victim and executed by the web browser.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-10-22
Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability by sending a crafted HTTP request to broadweb/system/opcImg.asp.
CVSS Score
8.8
EPSS Score
0.205
Published
2018-10-22


Contact Us

Shodan ® - All rights reserved