Known Vulnerabilities for Webaccess/nms by Advantech
Listed below are 10 of the newest known vulnerabilities associated with "Webaccess/nms" by "Advantech".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-32951 | WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized... | 5.3 - MEDIUM | 2021-10-27 | 2021-10-29 |
| CVE-2020-10631 | An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) c... | 9.8 - CRITICAL | 2020-04-09 | 2020-04-10 |
| CVE-2020-10629 | WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to r... | 7.5 - HIGH | 2020-04-09 | 2020-04-10 |
| CVE-2020-10625 | WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account. | 9.8 - CRITICAL | 2020-04-09 | 2020-04-10 |
| CVE-2020-10623 | Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions prio... | 6.5 - MEDIUM | 2020-04-09 | 2020-04-10 |
| CVE-2020-10621 | Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2). | 9.8 - CRITICAL | 2020-04-09 | 2020-04-10 |
| CVE-2020-10619 | An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control. | 9.1 - CRITICAL | 2020-04-09 | 2020-04-10 |
| CVE-2020-10617 | There are multiple ways an unauthenticated attacker could perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to... | 7.5 - HIGH | 2020-04-09 | 2020-04-09 |
| CVE-2020-10603 | WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system comm... | 8.8 - HIGH | 2020-04-09 | 2020-04-10 |
| CVE-2018-7495 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.... | 7.5 - HIGH | 2018-05-15 | 2019-10-09 |