Known Vulnerabilities for Webaccess/scada by Advantech
Listed below are 10 of the newest known vulnerabilities associated with "Webaccess/scada" by "Advantech".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-32956 | Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a malici... | 6.1 - MEDIUM | 2021-06-18 | 2021-06-24 |
| CVE-2021-32954 | Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to rem... | 6.5 - MEDIUM | 2021-06-18 | 2022-07-02 |
| CVE-2021-32943 | The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrar... | 9.8 - CRITICAL | 2021-08-10 | 2021-08-17 |
| CVE-2021-27436 | WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious J... | 6.1 - MEDIUM | 2021-03-18 | 2021-03-25 |
| CVE-2021-22676 | UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send ma... | 6.1 - MEDIUM | 2021-08-10 | 2021-08-17 |
| CVE-2021-22674 | The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized... | 6.5 - MEDIUM | 2021-08-10 | 2021-08-17 |
| CVE-2021-22669 | Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Ve... | 8.8 - HIGH | 2021-04-26 | 2021-05-07 |
| CVE-2020-13552 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0... | 8.8 - HIGH | 2021-02-17 | 2022-06-29 |
| CVE-2020-13551 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0... | 8.8 - HIGH | 2021-02-17 | 2022-06-29 |
| CVE-2020-13550 | A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially... | 7.7 - HIGH | 2021-02-17 | 2022-06-29 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Advantech | Webaccess/scada | 9.0.1 | All | All | All |
| Application | Advantech | Webaccess/scada | 8.3.2 | All | All | All |
| Application | Advantech | Webaccess/scada | 8.3 | All | All | All |
| Application | Advantech | Webaccess/scada | 8.2_20170817 | All | All | All |
| Application | Advantech | Webaccess/scada | 8.2 | All | All | All |
| Application | Advantech | Webaccess/scada | 8.1 | All | All | All |
| Application | Advantech | Webaccess/scada | 8.0 | All | All | All |
| Application | Advantech | Webaccess/scada | 7.2 | All | All | All |