Advantech
advantech
378 CVEs • 95 products
Products (95)
Click to collapseToggle
Products (95)
Click to collapse
CVEs (378)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Advantech 1Adam 5630 Firmware Jun 17, 2026 Sep 27, 2024 6.9 MEDIUM· v4 5.7 MEDIUM· v3 N/A· v2 Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process. |
Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with e...Show more |
Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information. |
Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials. |
1Advantech 3Eki 1521 Firmware Eki 1522 FirmwareEki 1524 FirmwareJun 17, 2026 Aug 8, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface. |
1Advantech 3Eki 1521 Firmware Eki 1522 FirmwareEki 1524 FirmwareJun 17, 2026 Aug 8, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface. |
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an a...Show more |
An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform...Show more |
Advantech R-SeeNet
versions 2.4.22
allows low-level users to access and load the content of local files.
|
Advantech R-SeeNet
versions 2.4.22
is installed with a hidden root-level user that is not available in the
users list. This hidden user has a password that cannot be changed by
users.
|
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.
|
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead...Show more |
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an...Show more |
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to...Show more |
1Advantech 3Eki 1521 Firmware Eki 1522 FirmwareEki 1524 FirmwareJun 17, 2026 May 8, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request. |
1Advantech 3Eki 1521 Firmware Eki 1522 FirmwareEki 1524 FirmwareJun 17, 2026 May 8, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request. |
1Advantech 3Eki 1521 Firmware Eki 1522 FirmwareEki 1524 FirmwareJun 17, 2026 May 8, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request. |
Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP code to delete .PDF files.
|
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.
|
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.
|