CVE-2023-1437
CRITICALAdvantech WebAccess/SCADA <9.1.4 - Memory Corruption
Title source: llmDescription
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.
Scores
CVSS v3
9.8
EPSS
0.0018
EPSS Percentile
39.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
CWE-822
Status
published
Products (1)
advantech/webaccess\/scada
< 9.1.4
Published
Aug 02, 2023
Tracked Since
Feb 18, 2026