← Back

Webaccess/scada

webaccess/scada

Vendor: Advantech • 29 CVEs

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Advantech
1Webaccess/scada
Jun 17, 2026
Feb 17, 2021
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folde...Show more
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Feb 17, 2021
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either repl...Show more
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Feb 17, 2021
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated...Show more
A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.Show less
1Advantech
1Webaccess/scada
Jun 17, 2026
Feb 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WebAccess/SCADA, Version 8.3. The software does not properly sanitize its inputs for SQL commands.
1Advantech
1Webaccess/scada
Jun 17, 2026
Feb 5, 2019
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
WebAccess/SCADA, Version 8.3. Specially crafted requests could allow a possible authentication bypass that could allow an attacker to obtain and manipulate sensitive information.
1Advantech
1Webaccess/scada
Jun 17, 2026
Feb 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WebAccess/SCADA, Version 8.3. An improper authentication vulnerability exists that could allow a possible authentication bypass allowing an attacker to upload malicious data.
1Advantech
1Webaccess/scada
Nov 21, 2024
Dec 19, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user supplied input may allow an attacker to cause the overflow of a buffer on the stack.
1Advantech
1Webaccess/scada
Jun 17, 2026
Jan 25, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the directory structure of the target device.
1Advantech
1Webaccess/scada
Jun 17, 2026
Jan 25, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands.