Advantech Vulnerabilities and Affected Products
Vulnerabilities associated with R-SeeNet.
Products
Clear product- WebAccess31 vulnerabilities
- EKI-6333AC-1GPO20 vulnerabilities
- EKI-6333AC-2G20 vulnerabilities
- EKI-6333AC-2GD20 vulnerabilities
- eki-6333ac-1gpo_firmware19 vulnerabilities
- eki-6333ac-2g_firmware19 vulnerabilities
- eki-6333ac-2gd_firmware19 vulnerabilities
- iView17 vulnerabilities
- WebAccess/SCADA16 vulnerabilities
- WebAccess/VPN12 vulnerabilities
- Advantech WebAccess9 vulnerabilities
- Advantech Wireless Sensing and Equipment (WISE)8 vulnerabilities
- R-SeeNet8 vulnerabilities
- EKI-15215 vulnerabilities
- EKI-15225 vulnerabilities
- EKI-15245 vulnerabilities
- ADAM-56304 vulnerabilities
- DeviceOn/iEdge4 vulnerabilities
- ADAM 55502 vulnerabilities
- adam-5630_firmware2 vulnerabilities
- HMI Designer2 vulnerabilities
- ADAM-36001 vulnerability
- ECOWatch SaaS-Composer1 vulnerability
- Hospital Quering Management1 vulnerability
- Hospital Queuing Management1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-5642CRITICAL | Advantech R-SeeNet Unauthenticated Read/WriteAdvantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information. CWE-200Oct 18, 2023 | CVSS9.8v3.1 | EPSS16.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2611CRITICAL | Advantech R-SeeNet Use of Hard-coded CredentialsAdvantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users. CWE-798Jun 22, 2023 | CVSS9.8v3.1 | EPSS0.668% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3256HIGH | Advantech R-SeeNet External Control of File Name or PathAdvantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files. | CVSS8.8v3.1 | EPSS0.647% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3387MEDIUM | Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP code to delete .PDF files. CWE-22Oct 27, 2022 | CVSS6.5v3.1 | EPSS14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3386CRITICAL | Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution. | CVSS9.8v3.1 | EPSS1.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3385CRITICAL | Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution. | CVSS9.8v3.1 | EPSS1.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-21805CRITICAL | advantech r-seenet Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary OS command execution. An attacker can send a crafted HTTP request to trigger this vulnerability. | CVSS9.8v3.1 | EPSS69.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-21801MEDIUM | advantech r-seenet Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution. | CVSS6.1v3.1 | EPSS63.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |