Known Vulnerabilities for Webaccess/scada by Advantech
Listed below are 10 of the newest known vulnerabilities associated with "Webaccess/scada" by "Advantech".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-32628 json | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attack... | 9.8 - CRITICAL | 2023-06-06 | 2023-06-12 |
| CVE-2023-32540 json | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attac... | 9.8 - CRITICAL | 2023-06-06 | 2023-06-12 |
| CVE-2023-22450 json | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker... | 7.2 - HIGH | 2023-06-06 | 2023-06-12 |
| CVE-2023-1437 json | All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the c... | 9.8 - CRITICAL | 2023-08-02 | 2024-02-01 |
| CVE-2021-32956 json | Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a malici... | 6.1 - MEDIUM | 2021-06-18 | 2021-06-24 |
| CVE-2021-32954 json | Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to rem... | 6.5 - MEDIUM | 2021-06-18 | 2022-07-02 |
| CVE-2021-32943 json | The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrar... | 9.8 - CRITICAL | 2021-08-10 | 2021-08-17 |
| CVE-2021-27436 json | WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious J... | 6.1 - MEDIUM | 2021-03-18 | 2021-03-25 |
| CVE-2021-22676 json | UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send ma... | 6.1 - MEDIUM | 2021-08-10 | 2021-08-17 |
| CVE-2021-22674 json | The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized... | 6.5 - MEDIUM | 2021-08-10 | 2021-08-17 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Advantech | Webaccess/scada | 9.0.1 | |||
| Application | Advantech | Webaccess/scada | 8.3.2 | |||
| Application | Advantech | Webaccess/scada | 8.3 | |||
| Application | Advantech | Webaccess/scada | 8.2_20170817 | |||
| Application | Advantech | Webaccess/scada | 8.2 | |||
| Application | Advantech | Webaccess/scada | 8.1 | |||
| Application | Advantech | Webaccess/scada | 8.0 | |||
| Application | Advantech | Webaccess/scada | 7.2 |