Webaccess

Vendor:

First CVE: Apr 12, 2014 · Active for 12 years

118
Total CVEs
More Total CVEs than 99% of tracked products
13.1
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Webaccess over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2014
12 years ago
Most Recent CVE
Oct 17, 2023
1,011 days ago

CVE Severity & Scoring

Webaccess118 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local13 (11.0%)
Network87 (73.7%)
Unknown18 (15.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low97 (82.2%)
High3 (2.5%)
Unknown18 (15.3%)
User Interaction
None83 (70.3%)
Unknown18 (15.3%)
Required17 (14.4%)
Privileges Required
Low19 (16.1%)
High1 (0.8%)
None80 (67.8%)
Unknown18 (15.3%)

Top CVEs

Signals from CVEs in this product scope (118 CVEs).

118 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows r
Jan 15, 20169.885NOYES
Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter,
Jul 19, 20147.577NOYES
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device.
Jan 5, 20189.870NOYES
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).
Feb 13, 20189.849NOYES
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied da
Nov 6, 20176.348NOYES
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.
Jan 5, 20189.845NOYES
Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.
Jan 15, 20169.845NONO
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerabi
Oct 31, 20186.539NOYES
Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code via unknown vectors.
Sep 11, 201510.039NOYES
Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability by sending
Oct 22, 20188.838NONO

Exploit Exposure

Signals from CVEs in this product scope (118 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
4.2% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
7.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (118 CVEs).

Media Mentions

Signals from CVEs in this product scope (118 CVEs).

Top CNAs Publishing CVEs For Webaccess

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.1.317.50.5%00
9.0.088.83.5%00
8.4.517.80.1%00
8.4.416.10.9%00
8.4.216.10.9%00
8.4.119.84.6%00
8.4.029.84.0%00
8.3.438.32.6%00
8.3.236.115.5%02
8.3.136.115.5%02
8.3.019.813.0%01
8.129.44.1%00
8.016.90.8%00