CVE-2017-5154 is a critical SQL injection vulnerability affecting Advantech WebAccess Version 8.1. An unauthenticated attacker can exploit this flaw by providing malformed input, potentially gaining administrative access to the application and its data. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, there is evidence of public exploit code on GitHub and significant community discussion, indicating potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.1CPE matchmatch criteria | cpe:2.3:a:advantech:webaccess:8.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Advantech WebAccess Multiple Vulnerabilities
Jan 19, 2017[R1] Advantech WebAccess Multiple Vulnerabilities
Jan 19, 2017[R1] Advantech WebAccess Multiple Vulnerabilities
Jan 19, 2017[R1] Advantech WebAccess Multiple Vulnerabilities
Jan 19, 2017