Записи Advantech
378 опубликованных записей вендора advantech.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 8 · 2,1 %
- Pre-auth RCE
- 92
- С записью об исправлении
- 3,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')70
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')37
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer32
- CWE-121 Stack-based Buffer Overflow27
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')26
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')24
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
378 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2016-0854Готовый эксплойт | Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer inadvantech · webaccess | Критическая9,8 | — | 77,0 % | 14 янв. 2016 г. |
60На этой неделе | CVE-2021-21805Proof of concept | An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).advantech · r-seenet · CWE-78 | Критическая9,8 | — | 69,8 % | 5 авг. 2021 г. |
57В плане | CVE-2022-2143Готовый эксплойт | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.advantech · iview · CWE-77 | Критическая9,8 | — | 59,4 % | 22 июл. 2022 г. |
54В плане | CVE-2017-16720Proof of concept | A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier.advantech · webaccess · CWE-22 | Критическая9,8 | — | 50,3 % | 5 янв. 2018 г. |
51В плане | CVE-2025-52694Proof of concept | Execution of arbitrary SQL commandsadvantech · iot edge linux docker · CWE-89 | Критическая9,8 | — | 40,4 % | 11 янв. 2026 г. |
50В плане | CVE-2021-22652Готовый эксплойт | Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacadvantech · iview · CWE-306 | Критическая9,8 | — | 36,8 % | 11 февр. 2021 г. |
48В плане | CVE-2014-2364Готовый эксплойт | Advantech WebAccess Stack-Based Buffer Overflowadvantech · advantech webaccess · CWE-121 | Высокая7,5 | — | 61,4 % | 19 июл. 2014 г. |
47В плане | CVE-2011-0340Готовый эксплойт | Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as dadvantech · advantech studio · CWE-119 | Критическая9,3 | — | 32,3 % | 4 мая 2011 г. |
47В плане | CVE-2016-0857Эксплойта нет | Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectadvantech · webaccess · CWE-119 | Критическая9,8 | — | 28,2 % | 14 янв. 2016 г. |
45В плане | CVE-2014-8387Proof of concept | cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shelladvantech · eki-6340 firmware · CWE-78 | Критическая9,0 | — | 30,9 % | 20 нояб. 2014 г. |
44В плане | CVE-2016-0856Эксплойта нет | Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vecadvantech · webaccess · CWE-119 | Критическая9,8 | — | 16,7 % | 14 янв. 2016 г. |
44В плане | CVE-2023-5642Эксплойта нет | Advantech R-SeeNet Unauthenticated Read/Writeadvantech · r-seenet · CWE-200 | Критическая9,8 | — | 16,7 % | 18 окт. 2023 г. |
44В плане | CVE-2022-2139Эксплойта нет | The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary coadvantech · iview · CWE-23 | Критическая9,8 | — | 15,6 % | 22 июл. 2022 г. |
43В плане | CVE-2021-21801Proof of concept | This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications.advantech · r-seenet · CWE-79 | Средняя6,1 | — | 63,4 % | 16 июл. 2021 г. |
43В плане | CVE-2018-6911Proof of concept | The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a singadvantech · webaccess · CWE-78 | Критическая9,8 | — | 12,8 % | 13 февр. 2018 г. |
43В плане | CVE-2021-22658Эксплойта нет | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Admadvantech · iview · CWE-89 | Критическая9,8 | — | 12,7 % | 11 февр. 2021 г. |
43В плане | CVE-2014-9208Proof of concept | Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitraadvantech · webaccess · CWE-119 | Критическая10,0 | — | 9,3 % | 11 сент. 2015 г. |
43В плане | CVE-2011-0488Эксплойта нет | Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and Iadvantech · advantech studio · CWE-119 | Критическая10,0 | — | 8,6 % | 18 янв. 2011 г. |
42В плане | CVE-2021-38408Эксплойта нет | A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the lengadvantech · webaccess · CWE-121 | Критическая9,8 | — | 11,6 % | 9 сент. 2021 г. |
42В плане | CVE-2019-10993Эксплойта нет | In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute aadvantech · webaccess · CWE-119 | Критическая9,8 | — | 10,7 % | 28 июн. 2019 г. |
42В плане | CVE-2021-38389Эксплойта нет | Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely executeadvantech · webaccess · CWE-121 | Критическая9,8 | — | 10,4 % | 18 окт. 2021 г. |
42В плане | CVE-2020-12002Эксплойта нет | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.advantech · webaccess · CWE-121 | Критическая9,8 | — | 9,1 % | 8 мая 2020 г. |
42В плане | CVE-2019-10991Эксплойта нет | In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validationadvantech · webaccess · CWE-787 | Критическая9,8 | — | 9,0 % | 28 июн. 2019 г. |
42В плане | CVE-2019-10989Эксплойта нет | In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation oadvantech · webaccess · CWE-787 | Критическая9,8 | — | 8,6 % | 28 июн. 2019 г. |
42В плане | CVE-2012-0242Proof of concept | Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string sadvantech · advantech webaccess · CWE-134 | Критическая10,0 | — | 7,2 % | 21 февр. 2012 г. |
- CVE-2016-085462На этой неделе
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in
КритическаяCVSS 9,8Готовый эксплойтEPSS 77 %advantech · webaccess14 янв. 2016 г.
- CVE-2021-2180560На этой неделе
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).
КритическаяCVSS 9,8Proof of conceptEPSS 70 %advantech · r-seenet5 авг. 2021 г.
- CVE-2022-214357В плане
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.
КритическаяCVSS 9,8Готовый эксплойтEPSS 59 %advantech · iview22 июл. 2022 г.
- CVE-2017-1672054В плане
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier.
КритическаяCVSS 9,8Proof of conceptEPSS 50 %advantech · webaccess5 янв. 2018 г.
- CVE-2025-5269451В плане
Execution of arbitrary SQL commands
КритическаяCVSS 9,8Proof of conceptEPSS 40 %advantech · iot edge linux docker11 янв. 2026 г.
- CVE-2021-2265250В плане
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attac
КритическаяCVSS 9,8Готовый эксплойтEPSS 37 %advantech · iview11 февр. 2021 г.
- CVE-2014-236448В плане
Advantech WebAccess Stack-Based Buffer Overflow
ВысокаяCVSS 7,5Готовый эксплойтEPSS 61 %advantech · advantech webaccess19 июл. 2014 г.
- CVE-2011-034047В плане
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as d
КритическаяCVSS 9,3Готовый эксплойтEPSS 32 %advantech · advantech studio4 мая 2011 г.
- CVE-2016-085747В плане
Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vect
КритическаяCVSS 9,8Эксплойта нетEPSS 28 %advantech · webaccess14 янв. 2016 г.
- CVE-2014-838745В плане
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell
КритическаяCVSS 9,0Proof of conceptEPSS 31 %advantech · eki-6340 firmware20 нояб. 2014 г.
- CVE-2016-085644В плане
Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vec
КритическаяCVSS 9,8Эксплойта нетEPSS 17 %advantech · webaccess14 янв. 2016 г.
- CVE-2023-564244В плане
Advantech R-SeeNet Unauthenticated Read/Write
КритическаяCVSS 9,8Эксплойта нетEPSS 17 %advantech · r-seenet18 окт. 2023 г.
- CVE-2022-213944В плане
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary co
КритическаяCVSS 9,8Эксплойта нетEPSS 16 %advantech · iview22 июл. 2022 г.
- CVE-2021-2180143В плане
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications.
СредняяCVSS 6,1Proof of conceptEPSS 63 %advantech · r-seenet16 июл. 2021 г.
- CVE-2018-691143В плане
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a sing
КритическаяCVSS 9,8Proof of conceptEPSS 13 %advantech · webaccess13 февр. 2018 г.
- CVE-2021-2265843В плане
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Adm
КритическаяCVSS 9,8Эксплойта нетEPSS 13 %advantech · iview11 февр. 2021 г.
- CVE-2014-920843В плане
Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitra
КритическаяCVSS 10,0Proof of conceptEPSS 9 %advantech · webaccess11 сент. 2015 г.
- CVE-2011-048843В плане
Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and I
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %advantech · advantech studio18 янв. 2011 г.
- CVE-2021-3840842В плане
A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the leng
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %advantech · webaccess9 сент. 2021 г.
- CVE-2019-1099342В плане
In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute a
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %advantech · webaccess28 июн. 2019 г.
- CVE-2021-3838942В плане
Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %advantech · webaccess18 окт. 2021 г.
- CVE-2020-1200242В плане
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %advantech · webaccess8 мая 2020 г.
- CVE-2019-1099142В плане
In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %advantech · webaccess28 июн. 2019 г.
- CVE-2019-1098942В плане
In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation o
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %advantech · webaccess28 июн. 2019 г.
- CVE-2012-024242В плане
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string s
КритическаяCVSS 10,0Proof of conceptEPSS 7 %advantech · advantech webaccess21 февр. 2012 г.