VYPR

Webaccess

by Advantech

CVEs (172)

  • CVE-2017-12719HigNov 6, 2017
    risk 0.49cvss 7.5epss 0.03

    An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A remote attacker is able to execute code to dereference a pointer within the program causing the application to become unavailable.

  • CVE-2017-12710HigAug 30, 2017
    risk 0.49cvss 7.5epss 0.02

    A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By submitting a specially crafted parameter, it is possible to inject arbitrary SQL statements that could allow an attacker to obtain sensitive information.

  • CVE-2016-0860HigJan 15, 2016
    risk 0.49cvss 7.5epss 0.05

    Buffer overflow in the BwpAlarm subsystem in Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service via a crafted RPC request.

  • CVE-2016-0855HigJan 15, 2016
    risk 0.49cvss 7.5epss 0.05

    Directory traversal vulnerability in Advantech WebAccess before 8.1 allows remote attackers to list arbitrary virtual-directory files via unspecified vectors.

  • CVE-2016-0853HigJan 15, 2016
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted input.

  • CVE-2016-0852HigJan 15, 2016
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirement and obtain file or folder access via unspecified vectors.

  • CVE-2016-0851HigJan 15, 2016
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service (out-of-bounds memory access) via unspecified vectors.

  • CVE-2025-34239HigNov 6, 2025
    risk 0.47cvss 7.2epss 0.02

    Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted…

  • CVE-2023-2866HigJun 7, 2023
    risk 0.47cvss 7.3epss 0.00

    If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.

  • CVE-2023-32628HigJun 6, 2023
    risk 0.47cvss 7.2epss 0.01

    In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution.

  • CVE-2023-32540HigJun 6, 2023
    risk 0.47cvss 7.2epss 0.01

    In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead…

  • CVE-2023-22450HigJun 6, 2023
    risk 0.47cvss 7.2epss 0.01

    In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.

  • CVE-2020-12010HigMay 8, 2020
    risk 0.46cvss 7.1epss 0.01

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control.

  • CVE-2018-15705MedOct 31, 2018
    risk 0.46cvss 6.5epss 0.12

    WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary…

  • CVE-2017-7929HigMay 6, 2017
    risk 0.46cvss 7.1epss 0.02

    An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to access restricted files or directories.

  • CVE-2018-15706MedOct 31, 2018
    risk 0.45cvss 6.5epss 0.32

    WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.

  • CVE-2017-14016MedNov 6, 2017
    risk 0.45cvss 6.3epss 0.16

    A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary…

  • CVE-2016-4525MedJun 25, 2016
    risk 0.43cvss 6.6epss 0.00

    Unspecified ActiveX controls in Advantech WebAccess before 8.1_20160519 allow remote authenticated users to obtain sensitive information or modify data via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.

  • CVE-2025-34247MedNov 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

  • CVE-2025-34246MedNov 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database…

Page 5 of 9