← Back

Webaccess/scada

webaccess/scada

Vendor: Advantech • 29 CVEs

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Advantech
1Webaccess/scada
Jun 17, 2026
Dec 18, 2025
5.3 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.
1Advantech
1Webaccess/scada
Jun 17, 2026
Dec 18, 2025
5.3 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.
1Advantech
1Webaccess/scada
Jun 17, 2026
Dec 18, 2025
7.2 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.
1Advantech
1Webaccess/scada
Jun 17, 2026
Dec 18, 2025
8.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.
1Advantech
1Webaccess/scada
Jun 17, 2026
Dec 18, 2025
5.3 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.
1Advantech
1Webaccess/scada
Jun 17, 2026
Aug 2, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an a...Show more
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files. Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Jun 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead...Show more
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution. Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Jun 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an...Show more
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution. Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Jun 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to...Show more
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution. Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Aug 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA version...Show more
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Aug 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection t...Show more
UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection to a malicious webpage, and unintended browser action on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Aug 10, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAcce...Show more
The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Jun 18, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage.
1Advantech
1Webaccess/scada
Jun 17, 2026
Jun 18, 2021
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary files on the file system.
1Advantech
1Webaccess/scada
Jun 17, 2026
Apr 26, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, which may allow a low-privileged user to update an administrator’s password...Show more
Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, which may allow a low-privileged user to update an administrator’s password and login as an administrator to escalate privileges on the system.Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Mar 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of the user’s cookie/se...Show more
WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser actions.Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Mar 3, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess,...Show more
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Feb 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.
1Advantech
1Webaccess/scada
Jun 17, 2026
Feb 17, 2021
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace...Show more
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Feb 17, 2021
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess,...Show more
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.Show less