Known Vulnerabilities for Webaccess/nms by Advantech
Listed below are 10 of the newest known vulnerabilities associated with "Webaccess/nms" by "Advantech".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-32951 json | WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized... | 5.3 - MEDIUM | 2021-10-27 | 2021-10-29 |
| CVE-2020-10631 json | An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) c... | 9.8 - CRITICAL | 2020-04-09 | 2020-04-10 |
| CVE-2020-10629 json | WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to r... | 7.5 - HIGH | 2020-04-09 | 2020-04-10 |
| CVE-2020-10625 json | WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account. | 9.8 - CRITICAL | 2020-04-09 | 2020-04-10 |
| CVE-2020-10623 json | Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions prio... | 6.5 - MEDIUM | 2020-04-09 | 2020-04-10 |
| CVE-2020-10621 json | Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2). | 9.8 - CRITICAL | 2020-04-09 | 2020-04-10 |
| CVE-2020-10619 json | An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control. | 9.1 - CRITICAL | 2020-04-09 | 2020-04-10 |
| CVE-2020-10617 json | There are multiple ways an unauthenticated attacker could perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to... | 7.5 - HIGH | 2020-04-09 | 2020-04-09 |
| CVE-2020-10603 json | WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system comm... | 8.8 - HIGH | 2020-04-09 | 2020-04-10 |
| CVE-2018-10591 json | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.... | 6.1 - MEDIUM | 2018-05-15 | 2019-10-09 |