VYPR

Vendor CVEs

Advantech

All CVEs

388 total · sorted by risk
  • CVE-2020-16213HigAug 6, 2020
    risk 0.51cvss 7.8epss 0.03

    Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, which may allow remote code execution,…

  • CVE-2020-16207HigAug 6, 2020
    risk 0.51cvss 7.8epss 0.04

    Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by opening specially crafted project files that may overflow the heap, which may allow remote code execution, disclosure/modification of…

  • CVE-2018-17910HigOct 29, 2018
    risk 0.51cvss 7.8epss 0.05

    WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing a buffer overflow condition that allows for arbitrary remote code execution.

  • CVE-2018-17908HigOct 29, 2018
    risk 0.51cvss 7.8epss 0.00

    WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the installation is complete. This could allow an attacker to run elevated arbitrary code.

  • CVE-2018-14828HigOct 23, 2018
    risk 0.51cvss 7.8epss 0.00

    Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perform actions at a system administrator level.

  • CVE-2018-8841HigMay 15, 2018
    risk 0.51cvss 7.8epss 0.00

    In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an improper privilege management vulnerability may…

  • CVE-2017-5175HigMay 9, 2018
    risk 0.51cvss 7.8epss 0.02

    Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within the search path resulting in execution of arbitrary code.

  • CVE-2018-8837HigApr 25, 2018
    risk 0.51cvss 7.8epss 0.02

    Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.

  • CVE-2018-8835HigApr 25, 2018
    risk 0.51cvss 7.8epss 0.02

    Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.

  • CVE-2018-8833HigApr 25, 2018
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.

  • CVE-2017-12705HigOct 25, 2017
    risk 0.51cvss 7.8epss 0.00

    A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to trigger a heap-based buffer overflow, which may crash the process and allow an attacker to execute arbitrary code.

  • CVE-2017-12717HigAug 30, 2017
    risk 0.51cvss 7.8epss 0.02

    An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A maliciously crafted dll file placed earlier in the search path may allow an attacker to execute code within the context of the application.

  • CVE-2017-12713HigAug 30, 2017
    risk 0.51cvss 7.8epss 0.00

    An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files and folders with ACLs that affect other users are allowed to be modified by non-administrator accounts.

  • CVE-2017-12711HigAug 30, 2017
    risk 0.51cvss 7.8epss 0.00

    An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A built-in user account has been granted a sensitive privilege that may allow a user to elevate to administrative privileges.

  • CVE-2016-9353HigFeb 13, 2017
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system and is encrypted with a static key hard-coded in the program. Attackers could reverse the admin account password for use.

  • CVE-2022-2135HigJul 22, 2022
    risk 0.50cvss 7.5epss 0.10

    The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information.

  • CVE-2020-13550HigFeb 17, 2021
    risk 0.50cvss 7.7epss 0.03

    A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.

  • CVE-2021-22654HigFeb 11, 2021
    risk 0.50cvss 7.5epss 0.12

    Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information.

  • CVE-2025-13373HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.

  • CVE-2025-59171HigNov 6, 2025
    risk 0.49cvss 7.5epss 0.01

    Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

  • CVE-2022-50594HigNov 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’…

  • CVE-2025-48891HigJul 11, 2025
    risk 0.49cvss 7.6epss 0.00

    A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to information disclosure…

  • CVE-2023-52335HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The…

  • CVE-2021-32932HigJun 11, 2021
    risk 0.49cvss 7.5epss 0.01

    The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182).

  • CVE-2019-18231HigMar 17, 2021
    risk 0.49cvss 7.5epss 0.01

    Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.

  • CVE-2021-22656HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.03

    Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files.

  • CVE-2020-25157HigOct 20, 2020
    risk 0.49cvss 7.5epss 0.01

    The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.

  • CVE-2020-14499HigJul 15, 2020
    risk 0.49cvss 7.5epss 0.02

    Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.

  • CVE-2020-12018HigMay 8, 2020
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exists that may allow access to unauthorized data.

  • CVE-2020-12014HigMay 8, 2020
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized and may allow an attacker to inject SQL commands.

  • CVE-2020-10629HigApr 9, 2020
    risk 0.49cvss 7.5epss 0.01

    WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files.

  • CVE-2020-10617HigApr 9, 2020
    risk 0.49cvss 7.5epss 0.01

    There are multiple ways an unauthenticated attacker could perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to gain access to sensitive information.

  • CVE-2019-3942HigApr 1, 2020
    risk 0.49cvss 7.5epss 0.01

    Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.

  • CVE-2019-18227HigOct 31, 2019
    risk 0.49cvss 7.5epss 0.03

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.

  • CVE-2019-16901HigSep 26, 2019
    risk 0.49cvss 7.5epss 0.01

    Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x0000000000000000 called from ntdll!RtlRaiseStatus+0x00000000000000b4.

  • CVE-2019-16900HigSep 26, 2019
    risk 0.49cvss 7.5epss 0.01

    Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c.

  • CVE-2019-16899HigSep 26, 2019
    risk 0.49cvss 7.5epss 0.01

    In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starting at PM_V3!CTagInfoThreadBase::GetNICInfo+0x0000000000512918.

  • CVE-2019-10983HigJun 28, 2019
    risk 0.49cvss 7.5epss 0.02

    In WebAccess/SCADA Versions 8.3.5 and prior, an out-of-bounds read vulnerability is caused by a lack of proper validation of user-supplied data. Exploitation of this vulnerability may allow disclosure of information.

  • CVE-2019-3941HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.

  • CVE-2019-6554HigApr 5, 2019
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service condition.

  • CVE-2018-14820HigOct 23, 2018
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allow an arbitrary file deletion when processing.

  • CVE-2018-7503HigMay 15, 2018
    risk 0.49cvss 7.5epss 0.03

    In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a path transversal vulnerability has been identified,…

  • CVE-2018-7501HigMay 15, 2018
    risk 0.49cvss 7.5epss 0.02

    In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several SQL injection vulnerabilities have been…

  • CVE-2018-7495HigMay 15, 2018
    risk 0.49cvss 7.5epss 0.02

    In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an external control of file name or path vulnerability…

  • CVE-2018-10590HigMay 15, 2018
    risk 0.49cvss 7.5epss 0.02

    In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an information exposure vulnerability through directory…

  • CVE-2017-16736HigJan 12, 2018
    risk 0.49cvss 7.5epss 0.02

    An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attacker to upload arbitrary files.

  • CVE-2017-16753HigJan 5, 2018
    risk 0.49cvss 7.5epss 0.02

    An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows some inputs that may cause the program to crash.

  • CVE-2017-16728HigJan 5, 2018
    risk 0.49cvss 7.5epss 0.02

    An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the program to use an invalid memory address, resulting in a program crash.

  • CVE-2017-12719HigNov 6, 2017
    risk 0.49cvss 7.5epss 0.03

    An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A remote attacker is able to execute code to dereference a pointer within the program causing the application to become unavailable.

  • CVE-2017-12710HigAug 30, 2017
    risk 0.49cvss 7.5epss 0.02

    A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By submitting a specially crafted parameter, it is possible to inject arbitrary SQL statements that could allow an attacker to obtain sensitive information.

Page 4 of 8