Vulnerabilities > Advantech > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-09-22 | CVE-2020-16202 | Incorrect Permission Assignment for Critical Resource vulnerability in Advantech Webaccess WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system privileges. | 7.2 |
2020-08-25 | CVE-2020-16245 | Path Traversal vulnerability in Advantech Iview 5.6 Advantech iView, Versions 5.7 and prior. | 7.5 |
2020-08-06 | CVE-2020-16229 | Type Confusion vulnerability in Advantech Webaccess/Hmi Designer 2.1/2.1.9.31 Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. | 7.8 |
2020-08-06 | CVE-2020-16217 | Double Free vulnerability in Advantech Webaccess/Hmi Designer 2.1/2.1.9.31 Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. | 7.8 |
2020-08-06 | CVE-2020-16213 | Out-of-bounds Write vulnerability in Advantech Webaccess/Hmi Designer 2.1/2.1.9.31 Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. | 7.8 |
2020-08-06 | CVE-2020-16207 | Out-of-bounds Write vulnerability in Advantech Webaccess/Hmi Designer 2.1/2.1.9.31 Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. | 7.8 |
2020-07-15 | CVE-2020-14503 | Improper Input Validation vulnerability in Advantech Iview 5.6 Advantech iView, versions 5.6 and prior, has an improper input validation vulnerability. | 7.5 |
2020-07-15 | CVE-2020-14507 | Path Traversal vulnerability in Advantech Iview 5.6 Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code. | 7.5 |
2020-07-15 | CVE-2020-14505 | Injection vulnerability in Advantech Iview 5.6 Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. | 7.5 |
2020-07-15 | CVE-2020-14497 | SQL Injection vulnerability in Advantech Iview 5.6 Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. | 7.5 |