Vulnerabilidades em Advantech

144 resultados
Análise Vexday

Com 142 CVEs catalogadas, o portfólio da Advantech apresenta 21 vulnerabilidades de severidade crítica e 4 com prova de conceito pública disponível, o que representa superfície de ataque concreta para agentes com capacidade de exploração. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero registros no CISA KEV, embora esse dado não elimine o risco, especialmente considerando que CVE-2014-2364 — a vulnerabilidade de maior destaque ativo — registra escore EPSS de 0,6138, indicando probabilidade relevante de exploração. A falha mais recorrente por tipo é CWE-89 (injeção de SQL), uma classe de vulnerabilidade bem documentada e com técnicas de exploração amplamente conhecidas, o que reforça a necessidade de atenção redobrada em ambientes que dependem de componentes Advantech expostos a redes. Equipes de segurança devem priorizar a revisão das vulnerabilidades críticas com PoC pública, particularmente em instalações de tecnologia operacional onde a janela de correção tende a ser mais restrita.

CVE-2014-2364Advantech WebAccess Stack-Based Buffer OverflowEPSS 61.4%CVE-2025-52694CRITICALExecution of arbitrary SQL commandsEPSS 37.9%CVE-2018-15706WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a dirEPSS 32.4%CVE-2018-15704Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentiallEPSS 21.5%CVE-2014-0763Advantech WebAccess SQL InjectionEPSS 19.2%CVE-2023-5642CRITICALAdvantech R-SeeNet Unauthenticated Read/WriteEPSS 16.7%CVE-2026-2670HIGHAdvantech WISE-6610 Background Management openvpn_apply os command injectionEPSS 16.3%CVE-2023-2575HIGHAuthenticated Buffer OverflowEPSS 15.5%CVE-2022-3387MEDIUM Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnEPSS 14.0%CVE-2018-15705WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesysteEPSS 12.2%CVE-2021-38389CRITICALAdvantech WebAccessEPSS 10.4%CVE-2019-6550Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple stack-based buffer overflow vulnerabilities, caused by a lack of proper validaEPSS 6.1%CVE-2018-8845In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prioEPSS 5.7%CVE-2018-14806Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code.EPSS 4.8%CVE-2023-2574HIGHAuthenticated Command InjectionEPSS 4.8%CVE-2023-2573HIGHAuthenticated Command InjectionEPSS 4.8%CVE-2025-53475HIGHAdvantech iView SQL InjectionEPSS 4.6%CVE-2019-3975Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbitrary code via a craEPSS 4.6%CVE-2018-14816Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified, which may allow an EPSS 4.1%CVE-2019-3940Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use thiEPSS 4.1%