Vulnerabilidades em Advantech

161 resultados
Análise Vexday

Com 142 CVEs catalogadas, o portfólio da Advantech apresenta 21 vulnerabilidades de severidade crítica e 4 com prova de conceito pública disponível, o que representa superfície de ataque concreta para agentes com capacidade de exploração. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero registros no CISA KEV, embora esse dado não elimine o risco, especialmente considerando que CVE-2014-2364 — a vulnerabilidade de maior destaque ativo — registra escore EPSS de 0,6138, indicando probabilidade relevante de exploração. A falha mais recorrente por tipo é CWE-89 (injeção de SQL), uma classe de vulnerabilidade bem documentada e com técnicas de exploração amplamente conhecidas, o que reforça a necessidade de atenção redobrada em ambientes que dependem de componentes Advantech expostos a redes. Equipes de segurança devem priorizar a revisão das vulnerabilidades críticas com PoC pública, particularmente em instalações de tecnologia operacional onde a janela de correção tende a ser mais restrita.

CVE-2022-50595CRITICALAdvantech iView < v5.7.04 Build 6425 ztp_search_value Parameter SQL Injection RCEEPSS 0.6%CVE-2018-10591In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prioEPSS 0.6%CVE-2025-14849HIGHAdvantech WebAccess/SCADA Unrestricted Upload of File with Dangerous TypeEPSS 0.6%CVE-2026-14161HIGHAdvantech|Hospital Queuing Management - Sensitive Data ExposureEPSS 0.5%CVE-2024-50358HIGHA CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKIEPSS 0.5%CVE-2025-48466HIGHModbus Command Injection without AuthenticationEPSS 0.5%CVE-2025-52577HIGHAdvantech iView SQL InjectionEPSS 0.5%CVE-2025-53515HIGHAdvantech iView SQL InjectionEPSS 0.5%CVE-2025-58423HIGHAdvantech DeviceOn/iEdge Path TraversalEPSS 0.5%CVE-2026-73169MEDIUMNozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilityEPSS 0.5%CVE-2026-73170HIGHNozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import wEPSS 0.5%CVE-2022-50591HIGHAdvantech iView < v5.7.04 Build 6425 ztp_config_id Parameter SQL Injection Information DisclosureEPSS 0.5%CVE-2026-73171HIGHNozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKEPSS 0.5%CVE-2023-4215MEDIUMAdvantech WebAccess Debug Messages Revealing Unnecessary InformationEPSS 0.5%CVE-2025-48469CRITICALUnauthenticated Firmware UploadEPSS 0.5%CVE-2025-48461MEDIUMWeak Session Cookie EntropyEPSS 0.5%CVE-2022-50594HIGHAdvantech iView < v5.7.04 Build 6425 data Parameter SQL Injection Information DisclosureEPSS 0.5%CVE-2025-13373HIGHAdvantech iView SQL InjectionEPSS 0.4%CVE-2024-50376HIGHA CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devicEPSS 0.4%CVE-2024-39275HIGHAdvantech ADAM-5630 Use of Persistent Cookies Containing Sensitive InformationEPSS 0.4%