9.8
CVSSv3

CVE-2023-1437

Published: 02/08/2023 Updated: 01/02/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9

Vulnerability Summary

All versions before 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an malicious user to gain access to the remote file system and the ability to execute commands and overwrite files.

Vulnerable Product Search on Vulmon Subscribe to Product

advantech webaccess\\/scada