Vulnerabilities
Vulnerable Software
Advantech:  >> Webaccess  >> 6.0  Security Vulnerabilities
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.
CVSS Score
9.8
EPSS Score
0.044
Published
2018-01-05
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device.
CVSS Score
9.8
EPSS Score
0.282
Published
2018-01-05
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple instances of a vulnerability that allows too much data to be written to a location on the stack.
CVSS Score
9.8
EPSS Score
0.004
Published
2018-01-05
An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the program to use an invalid memory address, resulting in a program crash.
CVSS Score
7.5
EPSS Score
0.006
Published
2018-01-05
An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows some inputs that may cause the program to crash.
CVSS Score
7.5
EPSS Score
0.005
Published
2018-01-05
An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A remote attacker is able to execute code to dereference a pointer within the program causing the application to become unavailable.
CVSS Score
7.5
EPSS Score
0.019
Published
2017-11-06
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.
CVSS Score
6.3
EPSS Score
0.192
Published
2017-11-06
An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A maliciously crafted dll file placed earlier in the search path may allow an attacker to execute code within the context of the application.
CVSS Score
7.8
EPSS Score
0.007
Published
2017-08-30
An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible authentication bypass that could allow remote code execution.
CVSS Score
9.8
EPSS Score
0.069
Published
2017-08-30
An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. String format specifiers based on user provided input are not properly validated, which could allow an attacker to execute arbitrary code.
CVSS Score
8.8
EPSS Score
0.004
Published
2017-08-30


Contact Us

Shodan ® - All rights reserved