Vulnerabilidades em Advantech

161 resultados
Análise Vexday

Com 142 CVEs catalogadas, o portfólio da Advantech apresenta 21 vulnerabilidades de severidade crítica e 4 com prova de conceito pública disponível, o que representa superfície de ataque concreta para agentes com capacidade de exploração. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero registros no CISA KEV, embora esse dado não elimine o risco, especialmente considerando que CVE-2014-2364 — a vulnerabilidade de maior destaque ativo — registra escore EPSS de 0,6138, indicando probabilidade relevante de exploração. A falha mais recorrente por tipo é CWE-89 (injeção de SQL), uma classe de vulnerabilidade bem documentada e com técnicas de exploração amplamente conhecidas, o que reforça a necessidade de atenção redobrada em ambientes que dependem de componentes Advantech expostos a redes. Equipes de segurança devem priorizar a revisão das vulnerabilidades críticas com PoC pública, particularmente em instalações de tecnologia operacional onde a janela de correção tende a ser mais restrita.

CVE-2018-15707Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulneEPSS 1.9%CVE-2025-34239HIGHAdvantech WebAccess/VPN < 1.1.5 Command Injection in AppManagementController.appUpgradeAction()EPSS 1.7%CVE-2026-73172CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.7%CVE-2014-2368Advantech WebAccess Unsafe ActiveX Control Marked Safe For ScriptingEPSS 1.7%CVE-2026-79698CRITICALAdvantech WISE-6610-NB Node-RED nodered_lib_apply command injectionEPSS 1.7%CVE-2018-10590In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prioEPSS 1.7%CVE-2018-7501In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prioEPSS 1.6%CVE-2014-2365Advantech WebAccess Improper Access ControlEPSS 1.6%CVE-2019-6554Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-serEPSS 1.6%CVE-2014-2367Advantech WebAccess Authentication Bypass IssuesEPSS 1.5%CVE-2024-50370CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.5%CVE-2024-50374CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.5%CVE-2014-0772Advantech WebAccess File and Directory Information ExposureEPSS 1.4%CVE-2014-0771Advantech WebAccess File and Directory Information ExposureEPSS 1.4%CVE-2024-50359HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%CVE-2022-3385CRITICAL Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overfloEPSS 1.3%CVE-2022-3386CRITICAL Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized EPSS 1.3%CVE-2014-2366Advantech WebAccess Cleartext Storage of Sensitive Information in MemoryEPSS 1.3%CVE-2023-52335HIGHAdvantech iView ConfigurationServlet SQL Injection Information Disclosure VulnerabilityEPSS 1.3%CVE-2024-50372CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%