Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
advantech vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-0770
Stack-based buffer overflow in Advantech WebAccess prior to 7.2 allows remote malicious users to execute arbitrary code via a long UserName parameter.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 7.0
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess 6.0
NA
CVE-2014-0771
The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess prior to 7.2 allows remote malicious users to read arbitrary files via a file: URL.
Advantech Advantech Webaccess 7.0
Advantech Advantech Webaccess 6.0
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
NA
CVE-2014-0772
The OpenUrlToBufferTimeout method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess prior to 7.2 allows remote malicious users to read arbitrary files via a file: URL.
Advantech Advantech Webaccess 6.0
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
Advantech Advantech Webaccess 7.0
NA
CVE-2014-2364
Multiple stack-based buffer overflows in Advantech WebAccess prior to 7.2 allow remote malicious users to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColo...
Advantech Advantech Webaccess 7.0
Advantech Advantech Webaccess 6.0
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
1 EDB exploit
NA
CVE-2014-2367
The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess prior to 7.2 allows remote malicious users to read arbitrary files via a crafted call.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 7.0
Advantech Advantech Webaccess 6.0
Advantech Advantech Webaccess 5.0
NA
CVE-2013-2299
Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) prior to 7.1 2013.05.30 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
Advantech Advantech Webaccess 6.0
1 EDB exploit
NA
CVE-2008-5848
The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote malicious users to obtain access through an HTTP session, and (1) monitor or (2) control the module's Modbus/TCP I/O activity.
Advantech Adam-6015
Advantech Adam-6022
Advantech Adam-6050w
Advantech Adam-6060
Advantech Adam-6050
Advantech Adam-6051
Advantech Adam-6024
Advantech Adam-6060w
Advantech Adam-6018
Advantech Adam-6501
Advantech Adam-6017
Advantech Adam-6051w
Advantech Adam-6066
Advantech Adam-6052
NA
CVE-2012-0234
SQL injection vulnerability in Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to execute arbitrary SQL commands via a malformed URL.
Advantech Advantech Webaccess
Advantech Advantech Webaccess 5.0
NA
CVE-2012-0236
Advantech/BroadWin WebAccess 7.0 and previous versions allows remote malicious users to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
NA
CVE-2012-0237
Advantech/BroadWin WebAccess prior to 7.0 allows remote malicious users to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.
Advantech Advantech Webaccess 5.0
Advantech Advantech Webaccess
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »