Vulnerabilities > Advantech > Webaccess > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-05-15 | CVE-2018-8841 | Improper Privilege Management vulnerability in Advantech products In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an improper privilege management vulnerability may allow an authenticated user to modify files when read access should only be given to the user. | 7.8 |
2018-05-15 | CVE-2018-7503 | Path Traversal vulnerability in Advantech products In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a path transversal vulnerability has been identified, which may allow an attacker to disclose sensitive information on the target. | 7.5 |
2018-05-15 | CVE-2018-7501 | SQL Injection vulnerability in Advantech products In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several SQL injection vulnerabilities have been identified, which may allow an attacker to disclose sensitive information from the host. | 7.5 |
2018-05-15 | CVE-2018-7495 | Path Traversal vulnerability in Advantech products In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an external control of file name or path vulnerability has been identified, which may allow an attacker to delete files. | 7.5 |
2018-05-15 | CVE-2018-10590 | File and Directory Information Exposure vulnerability in Advantech products In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an information exposure vulnerability through directory listing has been identified, which may allow an attacker to find important files that are not normally visible. | 7.5 |
2018-05-09 | CVE-2017-5175 | Uncontrolled Search Path Element vulnerability in Advantech Webaccess Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within the search path resulting in execution of arbitrary code. | 7.8 |
2018-01-12 | CVE-2017-16736 | Unrestricted Upload of File with Dangerous Type vulnerability in Advantech Webaccess An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. | 7.5 |
2018-01-05 | CVE-2017-16753 | Improper Input Validation vulnerability in Advantech Webaccess An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. | 7.5 |
2018-01-05 | CVE-2017-16728 | NULL Pointer Dereference vulnerability in Advantech Webaccess An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. | 7.5 |
2017-11-06 | CVE-2017-12719 | NULL Pointer Dereference vulnerability in Advantech Webaccess An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. | 7.5 |