📦

advantech_webaccess

Vendor: advantech

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 2 Remote Access
Total CVEs 155 Total Indexed
Avg. EPSS 4.06% Exploit Prob.
Latest CVE CVE-2014-0992 Sep 20

Security Vulnerability Index

Page 4 / 16
10.0 CVSS

GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: 4.31%
5.0 CVSS

uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request.

EPSS: 1.19%
10.0 CVSS

Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: 4.30%
6.4 CVSS

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.

EPSS: 1.29%
5.0 CVSS

Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."

EPSS: 1.28%
6.0 CVSS

Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: 0.50%
7.5 CVSS

SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.

EPSS: 1.23%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.

EPSS: 0.99%
10.0 CVSS

Buffer overflow in an ActiveX control in Advantech/BroadWin WebAccess before 7.0 might allow remote attackers to execute arbitrary code via a long string value in unspecified parameters.

EPSS: 4.30%
10.0 CVSS

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client system, and execute this batch file, via unspecified vectors.

EPSS: 2.15%