advantech kayıtları
advantech üreticisine ait 378 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 8 · %2,1
- Pre-auth RCE
- 92
- Düzeltme kaydı olan
- %3,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')70
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')37
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer32
- CWE-121 Stack-based Buffer Overflow27
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')26
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')24
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
378 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2016-0854Silahlaştırılmış | Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer inadvantech · webaccess | Kritik9,8 | — | %77,0 | 14 Oca 2016 |
60Bu hafta | CVE-2021-21805Kavram kanıtı | An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).advantech · r-seenet · CWE-78 | Kritik9,8 | — | %69,8 | 5 Ağu 2021 |
57Planlayın | CVE-2022-2143Silahlaştırılmış | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.advantech · iview · CWE-77 | Kritik9,8 | — | %59,4 | 22 Tem 2022 |
54Planlayın | CVE-2017-16720Kavram kanıtı | A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier.advantech · webaccess · CWE-22 | Kritik9,8 | — | %50,3 | 5 Oca 2018 |
51Planlayın | CVE-2025-52694Kavram kanıtı | Execution of arbitrary SQL commandsadvantech · iot edge linux docker · CWE-89 | Kritik9,8 | — | %40,4 | 11 Oca 2026 |
50Planlayın | CVE-2021-22652Silahlaştırılmış | Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacadvantech · iview · CWE-306 | Kritik9,8 | — | %36,8 | 11 Şub 2021 |
48Planlayın | CVE-2014-2364Silahlaştırılmış | Advantech WebAccess Stack-Based Buffer Overflowadvantech · advantech webaccess · CWE-121 | Yüksek7,5 | — | %61,4 | 19 Tem 2014 |
47Planlayın | CVE-2011-0340Silahlaştırılmış | Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as dadvantech · advantech studio · CWE-119 | Kritik9,3 | — | %32,3 | 4 May 2011 |
47Planlayın | CVE-2016-0857İstismar yok | Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectadvantech · webaccess · CWE-119 | Kritik9,8 | — | %28,2 | 14 Oca 2016 |
45Planlayın | CVE-2014-8387Kavram kanıtı | cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shelladvantech · eki-6340 firmware · CWE-78 | Kritik9,0 | — | %30,9 | 20 Kas 2014 |
44Planlayın | CVE-2016-0856İstismar yok | Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vecadvantech · webaccess · CWE-119 | Kritik9,8 | — | %16,7 | 14 Oca 2016 |
44Planlayın | CVE-2023-5642İstismar yok | Advantech R-SeeNet Unauthenticated Read/Writeadvantech · r-seenet · CWE-200 | Kritik9,8 | — | %16,7 | 18 Eki 2023 |
44Planlayın | CVE-2022-2139İstismar yok | The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary coadvantech · iview · CWE-23 | Kritik9,8 | — | %15,6 | 22 Tem 2022 |
43Planlayın | CVE-2021-21801Kavram kanıtı | This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications.advantech · r-seenet · CWE-79 | Orta6,1 | — | %63,4 | 16 Tem 2021 |
43Planlayın | CVE-2018-6911Kavram kanıtı | The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a singadvantech · webaccess · CWE-78 | Kritik9,8 | — | %12,8 | 13 Şub 2018 |
43Planlayın | CVE-2021-22658İstismar yok | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Admadvantech · iview · CWE-89 | Kritik9,8 | — | %12,7 | 11 Şub 2021 |
43Planlayın | CVE-2014-9208Kavram kanıtı | Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitraadvantech · webaccess · CWE-119 | Kritik10,0 | — | %9,3 | 11 Eyl 2015 |
43Planlayın | CVE-2011-0488İstismar yok | Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and Iadvantech · advantech studio · CWE-119 | Kritik10,0 | — | %8,6 | 18 Oca 2011 |
42Planlayın | CVE-2021-38408İstismar yok | A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the lengadvantech · webaccess · CWE-121 | Kritik9,8 | — | %11,6 | 9 Eyl 2021 |
42Planlayın | CVE-2019-10993İstismar yok | In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute aadvantech · webaccess · CWE-119 | Kritik9,8 | — | %10,7 | 28 Haz 2019 |
42Planlayın | CVE-2021-38389İstismar yok | Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely executeadvantech · webaccess · CWE-121 | Kritik9,8 | — | %10,4 | 18 Eki 2021 |
42Planlayın | CVE-2020-12002İstismar yok | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.advantech · webaccess · CWE-121 | Kritik9,8 | — | %9,1 | 8 May 2020 |
42Planlayın | CVE-2019-10991İstismar yok | In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validationadvantech · webaccess · CWE-787 | Kritik9,8 | — | %9,0 | 28 Haz 2019 |
42Planlayın | CVE-2019-10989İstismar yok | In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation oadvantech · webaccess · CWE-787 | Kritik9,8 | — | %8,6 | 28 Haz 2019 |
42Planlayın | CVE-2012-0242Kavram kanıtı | Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string sadvantech · advantech webaccess · CWE-134 | Kritik10,0 | — | %7,2 | 21 Şub 2012 |
- CVE-2016-085462Bu hafta
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in
KritikCVSS 9,8SilahlaştırılmışEPSS %77advantech · webaccess14 Oca 2016
- CVE-2021-2180560Bu hafta
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).
KritikCVSS 9,8Kavram kanıtıEPSS %70advantech · r-seenet5 Ağu 2021
- CVE-2022-214357Planlayın
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.
KritikCVSS 9,8SilahlaştırılmışEPSS %59advantech · iview22 Tem 2022
- CVE-2017-1672054Planlayın
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier.
KritikCVSS 9,8Kavram kanıtıEPSS %50advantech · webaccess5 Oca 2018
- CVE-2025-5269451Planlayın
Execution of arbitrary SQL commands
KritikCVSS 9,8Kavram kanıtıEPSS %40advantech · iot edge linux docker11 Oca 2026
- CVE-2021-2265250Planlayın
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attac
KritikCVSS 9,8SilahlaştırılmışEPSS %37advantech · iview11 Şub 2021
- CVE-2014-236448Planlayın
Advantech WebAccess Stack-Based Buffer Overflow
YüksekCVSS 7,5SilahlaştırılmışEPSS %61advantech · advantech webaccess19 Tem 2014
- CVE-2011-034047Planlayın
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as d
KritikCVSS 9,3SilahlaştırılmışEPSS %32advantech · advantech studio4 May 2011
- CVE-2016-085747Planlayın
Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vect
KritikCVSS 9,8İstismar yokEPSS %28advantech · webaccess14 Oca 2016
- CVE-2014-838745Planlayın
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell
KritikCVSS 9,0Kavram kanıtıEPSS %31advantech · eki-6340 firmware20 Kas 2014
- CVE-2016-085644Planlayın
Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vec
KritikCVSS 9,8İstismar yokEPSS %17advantech · webaccess14 Oca 2016
- CVE-2023-564244Planlayın
Advantech R-SeeNet Unauthenticated Read/Write
KritikCVSS 9,8İstismar yokEPSS %17advantech · r-seenet18 Eki 2023
- CVE-2022-213944Planlayın
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary co
KritikCVSS 9,8İstismar yokEPSS %16advantech · iview22 Tem 2022
- CVE-2021-2180143Planlayın
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications.
OrtaCVSS 6,1Kavram kanıtıEPSS %63advantech · r-seenet16 Tem 2021
- CVE-2018-691143Planlayın
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a sing
KritikCVSS 9,8Kavram kanıtıEPSS %13advantech · webaccess13 Şub 2018
- CVE-2021-2265843Planlayın
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Adm
KritikCVSS 9,8İstismar yokEPSS %13advantech · iview11 Şub 2021
- CVE-2014-920843Planlayın
Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitra
KritikCVSS 10,0Kavram kanıtıEPSS %9advantech · webaccess11 Eyl 2015
- CVE-2011-048843Planlayın
Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and I
KritikCVSS 10,0İstismar yokEPSS %9advantech · advantech studio18 Oca 2011
- CVE-2021-3840842Planlayın
A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the leng
KritikCVSS 9,8İstismar yokEPSS %12advantech · webaccess9 Eyl 2021
- CVE-2019-1099342Planlayın
In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute a
KritikCVSS 9,8İstismar yokEPSS %11advantech · webaccess28 Haz 2019
- CVE-2021-3838942Planlayın
Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute
KritikCVSS 9,8İstismar yokEPSS %10advantech · webaccess18 Eki 2021
- CVE-2020-1200242Planlayın
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
KritikCVSS 9,8İstismar yokEPSS %9advantech · webaccess8 May 2020
- CVE-2019-1099142Planlayın
In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation
KritikCVSS 9,8İstismar yokEPSS %9advantech · webaccess28 Haz 2019
- CVE-2019-1098942Planlayın
In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation o
KritikCVSS 9,8İstismar yokEPSS %9advantech · webaccess28 Haz 2019
- CVE-2012-024242Planlayın
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string s
KritikCVSS 10,0Kavram kanıtıEPSS %7advantech · advantech webaccess21 Şub 2012