📦

webaccess

Vendor: advantech

Actively Exploited 0 CISA KEV List
PoC / Exploits 11 Code Available
Total RCEs 29 Remote Access
Total CVEs 431 Total Indexed
Avg. EPSS 5.62% Exploit Prob.
Latest CVE CVE-2023-4215 Oct 17

Security Vulnerability Index

Page 11 / 44
8.8 CVSS

Cross-site request forgery (CSRF) vulnerability in Advantech WebAccess before 8.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: 0.90%
5.3 CVSS

Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.

EPSS: 1.77%
6.9 CVSS

Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_20150816 allow remote attackers to execute arbitrary code via a crafted file that triggers long string arguments to functions.

EPSS: 0.79%
10.0 CVSS
CVE-2014-9208
Exploit Found

Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code via unknown vectors.

EPSS: 9.26%
7.2 CVSS

Stack-based buffer overflow in Advantech WebAccess, formerly BroadWin WebAccess, before 8.0 allows remote attackers to execute arbitrary code via a crafted ip_address parameter in an HTML document.

EPSS: 1.05%
2.1 CVSS

Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.

EPSS: 0.37%
10.0 CVSS
CVE-2011-4041
RCE Exploit Found

webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.

EPSS: 17.90%