Vulnerabilities
Vulnerable Software
Advantech:  >> Webaccess Hmi Designer  Security Vulnerabilities
This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser action.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-11-15
This vulnerability could allow an attacker to disclose information and execute arbitrary code on affected installations of WebAccess/MHI Designer
CVSS Score
7.8
EPSS Score
0.001
Published
2021-11-15
In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution.
CVSS Score
8.8
EPSS Score
0.008
Published
2019-08-02
Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
CVSS Score
7.8
EPSS Score
0.008
Published
2018-04-25
Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
CVSS Score
7.8
EPSS Score
0.004
Published
2018-04-25
Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.
CVSS Score
7.8
EPSS Score
0.004
Published
2018-04-25


Contact Us

Shodan ® - All rights reserved