📦

webaccess\/scada

Vendor: advantech

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 7 Remote Access
Total CVEs 39 Total Indexed
Avg. EPSS 1.24% Exploit Prob.
Latest CVE CVE-2025-67653 Dec 18

Security Vulnerability Index

Page 1 / 4
5.3 CVSS

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

EPSS: 0.63%
5.3 CVSS

Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

EPSS: 0.29%
7.2 CVSS

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

EPSS: 0.82%
8.7 CVSS

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

EPSS: 0.54%
5.3 CVSS

Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.

EPSS: 0.58%
9.8 CVSS

All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.

EPSS: 2.80%
7.2 CVSS

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution.

EPSS: 0.71%
7.2 CVSS

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.

EPSS: 0.90%
7.2 CVSS

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.

EPSS: 0.83%
9.8 CVSS

The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).

EPSS: 1.87%