CVE-2024-2453

MEDIUM

Advantech WebAccess/SCADA - SQL Injection

Title source: llm
STIX 2.1

Description

There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-081-01

Scores

CVSS v3 6.4
EPSS 0.0009
EPSS Percentile 25.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Advantech/WebAccess/SCADA 9.1.5U
Published Mar 21, 2024
Tracked Since Feb 18, 2026