📦

webaccess

Vendor: advantech

Actively Exploited 0 CISA KEV List
PoC / Exploits 11 Code Available
Total RCEs 29 Remote Access
Total CVEs 431 Total Indexed
Avg. EPSS 5.62% Exploit Prob.
Latest CVE CVE-2023-4215 Oct 17

Security Vulnerability Index

Page 2 / 44
7.5 CVSS

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exists that may allow access to unauthorized data.

EPSS: 1.53%
7.5 CVSS

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized and may allow an attacker to inject SQL commands.

EPSS: 1.53%
7.1 CVSS

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control.

EPSS: 1.01%
9.8 CVSS

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.

EPSS: 3.69%
9.8 CVSS

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.

EPSS: 9.08%
9.8 CVSS

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.

EPSS: 7.06%
7.5 CVSS

Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.

EPSS: 1.40%
8.8 CVSS

In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.

EPSS: 2.12%
9.8 CVSS

Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (memory corruption) due to a stack-based buffer overflow when handling IOCTL 70533 RPC messages.

EPSS: 3.61%
9.8 CVSS

In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote code execution, data exfiltration, or cause a system crash.

EPSS: 2.86%