📦 Webaccess\/nms

by Advantech

🔍 What is Webaccess\/nms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-10619

CRITICAL CVSS 9.1 Apr 9, 2020

This vulnerability allows attackers to delete arbitrary files on WebAccess/NMS systems by exploiting improper input validation in URL handling. Affected systems are Advantech WebAccess/NMS versions pr...

CVE-2020-10625

CRITICAL CVSS 9.8 Apr 9, 2020

This vulnerability allows unauthenticated remote attackers to create new administrator accounts in Advantech WebAccess/NMS network management software. Systems running versions prior to 3.0.2 are affe...

CVE-2020-10631

CRITICAL CVSS 9.8 Apr 9, 2020

This vulnerability allows attackers to perform directory traversal attacks on Advantech WebAccess/NMS systems, enabling unauthorized file deletion or reading outside the intended directory structure. ...

CVE-2020-10621

CRITICAL CVSS 9.8 Apr 9, 2020

This vulnerability allows unauthenticated attackers to upload and execute arbitrary files on Advantech WebAccess/NMS systems. It affects all versions prior to 3.0.2, enabling remote code execution on ...

CVE-2018-10589

CRITICAL CVSS 9.8 May 15, 2018

A path traversal vulnerability in Advantech WebAccess allows attackers to execute arbitrary code by manipulating file paths. This affects multiple WebAccess products including SCADA systems used in in...

CVE-2018-7497

CRITICAL CVSS 9.8 May 15, 2018

This vulnerability allows attackers to execute arbitrary code on Advantech WebAccess systems by exploiting untrusted pointer dereference flaws. Affected systems include multiple WebAccess versions, We...

CVE-2018-7505

CRITICAL CVSS 9.8 May 15, 2018

This vulnerability allows unauthenticated attackers to upload arbitrary files via TFTP to Advantech WebAccess systems, potentially leading to remote code execution. It affects multiple WebAccess produ...

CVE-2018-8845

CRITICAL CVSS 9.8 May 15, 2018

This vulnerability allows remote attackers to execute arbitrary code on affected Advantech WebAccess systems through a heap-based buffer overflow. It affects multiple WebAccess products and versions, ...

CVE-2020-10617

HIGH CVSS 7.5 Apr 9, 2020

Unauthenticated attackers can perform SQL injection attacks on Advantech WebAccess/NMS versions before 3.0.2 to access sensitive information. This affects industrial control systems using this network...