📦

webaccess

Vendor: advantech

Actively Exploited 0 CISA KEV List
PoC / Exploits 11 Code Available
Total RCEs 29 Remote Access
Total CVEs 431 Total Indexed
Avg. EPSS 5.62% Exploit Prob.
Latest CVE CVE-2023-4215 Oct 17

Security Vulnerability Index

Page 4 / 44
9.8 CVSS

Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 81024 RPC call.

EPSS: 3.91%
9.8 CVSS

Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 10012 RPC call.

EPSS: 3.99%
6.1 CVSS

Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; however, some former Zarafa Webapp customers use the related Kopano product instead.

EPSS: 5.17%
7.5 CVSS

Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.

EPSS: 2.39%
9.8 CVSS

Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.

EPSS: 4.08%
7.5 CVSS

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service condition.

EPSS: 1.57%
9.8 CVSS

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplied data, may allow remote code execution.

EPSS: 3.27%
9.8 CVSS

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple stack-based buffer overflow vulnerabilities, caused by a lack of proper validation of the length of user-supplied data, may allow remote code execution.

EPSS: 6.09%
5.4 CVSS
CVE-2018-15707
Exploit Found

Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.

EPSS: 1.88%
6.5 CVSS

WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.

EPSS: 32.37%