Vulnerabilidades en Advantech

161 resultados
Análisis Vexday

Com 142 CVEs catalogadas, o portfólio da Advantech apresenta 21 vulnerabilidades de severidade crítica e 4 com prova de conceito pública disponível, o que representa superfície de ataque concreta para agentes com capacidade de exploração. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero registros no CISA KEV, embora esse dado não elimine o risco, especialmente considerando que CVE-2014-2364 — a vulnerabilidade de maior destaque ativo — registra escore EPSS de 0,6138, indicando probabilidade relevante de exploração. A falha mais recorrente por tipo é CWE-89 (injeção de SQL), uma classe de vulnerabilidade bem documentada e com técnicas de exploração amplamente conhecidas, o que reforça a necessidade de atenção redobrada em ambientes que dependem de componentes Advantech expostos a redes. Equipes de segurança devem priorizar a revisão das vulnerabilidades críticas com PoC pública, particularmente em instalações de tecnologia operacional onde a janela de correção tende a ser mais restrita.

CVE-2024-50373CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%CVE-2024-50371CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%CVE-2022-22987CRITICALAdvantech ADAM-3600EPSS 1.2%CVE-2023-4203CRITICALStored Cross-Site ScriptingEPSS 1.1%CVE-2024-50366HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50363HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50369HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50364HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50365HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50360HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50362HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50367HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50368HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50375CRITICALA CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AEPSS 1.0%CVE-2023-4202CRITICALStored Cross-Site ScriptingEPSS 1.0%CVE-2026-73176HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.0%CVE-2026-73165HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.0%CVE-2026-73167HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.0%CVE-2021-32951MEDIUMAdvantech WebAccess/NMS Improper AuthenticationEPSS 0.9%CVE-2025-14850HIGHAdvantech WebAccess/SCADA Improper Limitation of a Pathname to a Restricted DirectoryEPSS 0.9%