VYPR

Vendor CVEs

Advantech

All CVEs

405 total · sorted by risk
  • CVE-2025-14252HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, resulting in privilege escalation, arbitrary code execution, and information disclosure. This issue affects Advantech SUSI:…

  • CVE-2022-3323HigSep 27, 2022
    risk 0.51cvss 7.5epss 0.29

    An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration…

  • CVE-2021-40397HigJan 28, 2022
    risk 0.51cvss 7.8epss 0.01

    A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-21912HigDec 22, 2021
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a…

  • CVE-2021-21911HigDec 22, 2021
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a…

  • CVE-2021-21910HigDec 22, 2021
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a…

  • CVE-2021-42706HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    This vulnerability could allow an attacker to disclose information and execute arbitrary code on affected installations of WebAccess/MHI Designer

  • CVE-2021-33004HigJun 24, 2021
    risk 0.51cvss 7.8epss 0.01

    The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).

  • CVE-2021-33002HigJun 24, 2021
    risk 0.51cvss 7.8epss 0.01

    Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction is require on the WebAccess HMI Designer (versions 2.1.9.95 and prior).

  • CVE-2021-33000HigJun 24, 2021
    risk 0.51cvss 7.8epss 0.01

    Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).

  • CVE-2020-13554HigMar 3, 2021
    risk 0.51cvss 7.8epss 0.01

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to…

  • CVE-2020-16202HigSep 22, 2020
    risk 0.51cvss 7.8epss 0.00

    WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system privileges.

  • CVE-2020-16229HigAug 6, 2020
    risk 0.51cvss 7.8epss 0.03

    Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a type confusion condition, which may allow remote code execution, disclosure/modification of information, or cause…

  • CVE-2020-16217HigAug 6, 2020
    risk 0.51cvss 7.8epss 0.03

    Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by processing specially crafted project files may allow remote code execution, disclosure/modification of information, or cause the application to crash.

  • CVE-2020-16215HigAug 6, 2020
    risk 0.51cvss 7.8epss 0.04

    Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a stack-based buffer overflow, which may allow remote code execution, disclosure/modification of information, or…

  • CVE-2020-16213HigAug 6, 2020
    risk 0.51cvss 7.8epss 0.03

    Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, which may allow remote code execution,…

  • CVE-2020-16207HigAug 6, 2020
    risk 0.51cvss 7.8epss 0.04

    Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by opening specially crafted project files that may overflow the heap, which may allow remote code execution, disclosure/modification of…

  • CVE-2018-17910HigOct 29, 2018
    risk 0.51cvss 7.8epss 0.07

    WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing a buffer overflow condition that allows for arbitrary remote code execution.

  • CVE-2018-17908HigOct 29, 2018
    risk 0.51cvss 7.8epss 0.01

    WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the installation is complete. This could allow an attacker to run elevated arbitrary code.

  • CVE-2018-14828HigOct 23, 2018
    risk 0.51cvss 7.8epss 0.00

    Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perform actions at a system administrator level.

  • CVE-2018-8841HigMay 15, 2018
    risk 0.51cvss 7.8epss 0.00

    In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an improper privilege management vulnerability may…

  • CVE-2017-5175HigMay 9, 2018
    risk 0.51cvss 7.8epss 0.02

    Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within the search path resulting in execution of arbitrary code.

  • CVE-2018-8837HigApr 25, 2018
    risk 0.51cvss 7.8epss 0.03

    Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.

  • CVE-2018-8835HigApr 25, 2018
    risk 0.51cvss 7.8epss 0.03

    Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.

  • CVE-2018-8833HigApr 25, 2018
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.

  • CVE-2017-12705HigOct 25, 2017
    risk 0.51cvss 7.8epss 0.00

    A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to trigger a heap-based buffer overflow, which may crash the process and allow an attacker to execute arbitrary code.

  • CVE-2017-12717HigAug 30, 2017
    risk 0.51cvss 7.8epss 0.04

    An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A maliciously crafted dll file placed earlier in the search path may allow an attacker to execute code within the context of the application.

  • CVE-2017-12713HigAug 30, 2017
    risk 0.51cvss 7.8epss 0.00

    An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files and folders with ACLs that affect other users are allowed to be modified by non-administrator accounts.

  • CVE-2017-12711HigAug 30, 2017
    risk 0.51cvss 7.8epss 0.00

    An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A built-in user account has been granted a sensitive privilege that may allow a user to elevate to administrative privileges.

  • CVE-2016-9353HigFeb 13, 2017
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system and is encrypted with a static key hard-coded in the program. Attackers could reverse the admin account password for use.

  • CVE-2022-2135HigJul 22, 2022
    risk 0.50cvss 7.5epss 0.10

    The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information.

  • CVE-2020-13550HigFeb 17, 2021
    risk 0.50cvss 7.7epss 0.03

    A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.

  • CVE-2021-22654HigFeb 11, 2021
    risk 0.50cvss 7.5epss 0.12

    Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information.

  • CVE-2025-13373HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.

  • CVE-2025-59171HigNov 6, 2025
    risk 0.49cvss 7.5epss 0.01

    Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

  • CVE-2022-50594HigNov 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’…

  • CVE-2025-48891HigJul 11, 2025
    risk 0.49cvss 7.6epss 0.00

    A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to information disclosure…

  • CVE-2023-52335HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The…

  • CVE-2021-32932HigJun 11, 2021
    risk 0.49cvss 7.5epss 0.01

    The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182).

  • CVE-2019-18231HigMar 17, 2021
    risk 0.49cvss 7.5epss 0.01

    Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.

  • CVE-2021-22656HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.03

    Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files.

  • CVE-2020-25157HigOct 20, 2020
    risk 0.49cvss 7.5epss 0.01

    The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.

  • CVE-2020-14499HigJul 15, 2020
    risk 0.49cvss 7.5epss 0.02

    Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.

  • CVE-2020-12018HigMay 8, 2020
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exists that may allow access to unauthorized data.

  • CVE-2020-12014HigMay 8, 2020
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized and may allow an attacker to inject SQL commands.

  • CVE-2020-10629HigApr 9, 2020
    risk 0.49cvss 7.5epss 0.01

    WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files.

  • CVE-2020-10617HigApr 9, 2020
    risk 0.49cvss 7.5epss 0.01

    There are multiple ways an unauthenticated attacker could perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to gain access to sensitive information.

  • CVE-2019-3942HigApr 1, 2020
    risk 0.49cvss 7.5epss 0.01

    Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.

  • CVE-2019-18227HigOct 31, 2019
    risk 0.49cvss 7.5epss 0.03

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.

  • CVE-2019-16901HigSep 26, 2019
    risk 0.49cvss 7.5epss 0.01

    Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x0000000000000000 called from ntdll!RtlRaiseStatus+0x00000000000000b4.

Page 4 of 9