Advantech Vulnerabilities and Affected Products
Vulnerabilities associated with Advantech WebAccess.
Products
Clear product- WebAccess31 vulnerabilities
- EKI-6333AC-1GPO20 vulnerabilities
- EKI-6333AC-2G20 vulnerabilities
- EKI-6333AC-2GD20 vulnerabilities
- eki-6333ac-1gpo_firmware19 vulnerabilities
- eki-6333ac-2g_firmware19 vulnerabilities
- eki-6333ac-2gd_firmware19 vulnerabilities
- iView17 vulnerabilities
- WebAccess/SCADA16 vulnerabilities
- WebAccess/VPN12 vulnerabilities
- Advantech WebAccess9 vulnerabilities
- Advantech Wireless Sensing and Equipment (WISE)8 vulnerabilities
- R-SeeNet8 vulnerabilities
- EKI-15215 vulnerabilities
- EKI-15225 vulnerabilities
- EKI-15245 vulnerabilities
- ADAM-56304 vulnerabilities
- DeviceOn/iEdge4 vulnerabilities
- ADAM 55502 vulnerabilities
- adam-5630_firmware2 vulnerabilities
- HMI Designer2 vulnerabilities
- ADAM-36001 vulnerability
- ECOWatch SaaS-Composer1 vulnerability
- Hospital Quering Management1 vulnerability
- Hospital Queuing Management1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-15706MEDIUM | WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API. CWE-22Oct 31, 2018 | CVSS6.5v3.0 | EPSS32.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15705MEDIUM | Advantech WebAccess SCADA 8.3.2 - Remote Code ExecutionWADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code. CWE-22Oct 31, 2018 | CVSS6.5v3.0 | EPSS12.2% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15707MEDIUM | Advantech WebAccess SCADA 8.3.2 - Remote Code ExecutionAdvantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things. CWE-79Oct 31, 2018 | CVSS5.4v3.0 | EPSS1.88% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-14820HIGH | Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allow an arbitrary file deletion when processing. | CVSS7.5v3.0 | EPSS2.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-14806CRITICAL | Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code. CWE-22Oct 23, 2018 | CVSS9.8v3.0 | EPSS4.78% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-14816CRITICAL | Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified, which may allow an attacker to execute arbitrary code. | CVSS9.8v3.1 | EPSS4.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-14828HIGH | Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perform actions at a system administrator level. CWE-269Oct 23, 2018 | CVSS7.8v3.0 | EPSS0.407% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15704HIGH | Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability by sending a crafted HTTP request to broadweb/system/opcImg.asp. CWE-787Oct 22, 2018 | CVSS8.8v3.0 | EPSS21.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15703MEDIUM | Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply malicious HTML or JavaScript code to WebAccess, which is then reflected back to the victim and executed by the web browser. CWE-79Oct 22, 2018 | CVSS6.1v3.0 | EPSS0.88% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |