CVE-2023-1437

CRITICAL

Advantech WebAccess/SCADA <9.1.4 - Memory Corruption

Title source: llm
STIX 2.1

Description

All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.

Scores

CVSS v3 9.8
EPSS 0.0018
EPSS Percentile 39.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119 CWE-822
Status published
Products (1)
advantech/webaccess\/scada < 9.1.4
Published Aug 02, 2023
Tracked Since Feb 18, 2026