Advantech WebAccess/SCADA 9.0.1

CPE Details

Advantech WebAccess/SCADA 9.0.1
9.0.1
2021-02-18
14h17 +00:00
2021-02-18
14h17 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:advantech:webaccess\/scada:9.0.1:*:*:*:*:*:*:*

Informations

Vendor

advantech

Product

webaccess\/scada

Version

9.0.1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-1437 2023-08-02 22h30 +00:00 All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.
9.8
Critique
CVE-2023-22450 2023-06-05 23h17 +00:00 In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.
7.2
Haute
CVE-2023-32540 2023-06-05 23h16 +00:00 In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
9.8
Critique
CVE-2023-32628 2023-06-05 23h14 +00:00 In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution.
9.8
Critique
CVE-2021-32954 2021-06-18 11h53 +00:00 Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary files on the file system.
6.5
Moyen
CVE-2021-32956 2021-06-18 11h52 +00:00 Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage.
6.1
Moyen
CVE-2021-22669 2021-04-26 16h59 +00:00 Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, which may allow a low-privileged user to update an administrator’s password and login as an administrator to escalate privileges on the system.
8.8
Haute
CVE-2020-13554 2021-03-03 15h14 +00:00 An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
7.8
Haute
CVE-2020-13555 2021-02-17 17h23 +00:00 An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
8.8
Haute
CVE-2020-13553 2021-02-17 17h20 +00:00 An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
8.8
Haute
CVE-2020-13551 2021-02-17 17h17 +00:00 An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
8.8
Haute
CVE-2020-13552 2021-02-17 17h16 +00:00 An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
8.8
Haute
CVE-2020-13550 2021-02-17 17h10 +00:00 A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.
7.7
Haute