📦 Webaccess\/scada

by Advantech

🔍 What is Webaccess\/scada?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-1437

CRITICAL CVSS 9.8 Aug 2, 2023

This vulnerability in Advantech WebAccess/SCADA allows attackers to send malicious RPC arguments containing raw memory pointers that the server uses without validation. This could enable remote code e...

CVE-2021-32943

CRITICAL CVSS 9.8 Aug 10, 2021

This vulnerability allows remote attackers to execute arbitrary code on Advantech WebAccess/SCADA systems via a stack-based buffer overflow. Attackers can potentially take full control of affected sys...

CVE-2025-14849

HIGH CVSS 8.8 Dec 18, 2025

Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, allowing attackers to upload malicious files to the server. This can lead to remote code execution, potentially compromising indust...

CVE-2025-14850

HIGH CVSS 8.1 Dec 18, 2025

Advantech WebAccess/SCADA is vulnerable to directory traversal that allows attackers to delete arbitrary files on the system. This affects industrial control systems using Advantech's SCADA software, ...

CVE-2023-32540

HIGH CVSS 7.2 Jun 6, 2023

This vulnerability in Advantech WebAccess/SCADA allows attackers to overwrite any file on the operating system, potentially leading to arbitrary code execution. It affects WebAccess/SCADA v9.1.3 and e...

CVE-2021-22669

HIGH CVSS 8.8 Apr 26, 2021

This vulnerability allows low-privileged users in Advantech WebAccess/SCADA to reset administrator passwords and gain full system control through privilege escalation. It affects WebAccess/SCADA versi...

CVE-2020-13554

HIGH CVSS 7.8 Mar 3, 2021

This vulnerability allows local attackers to escalate privileges to NT SYSTEM level by exploiting insecure file permissions in Advantech WebAccess/SCADA installation. Attackers can replace binaries or...

CVE-2025-67653

MEDIUM CVSS 4.3 Dec 18, 2025

Advantech WebAccess/SCADA is vulnerable to directory traversal (CWE-22), allowing attackers to check if arbitrary files exist on the system. This affects organizations using Advantech's industrial con...

CVE-2025-46268

MEDIUM CVSS 6.3 Dec 18, 2025

Advantech WebAccess/SCADA is vulnerable to SQL injection, allowing attackers to execute arbitrary SQL commands on the database. This affects industrial control systems using vulnerable versions of Adv...

CVE-2025-14848

MEDIUM CVSS 4.3 Dec 18, 2025

Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, allowing attackers to determine if arbitrary files exist on the system. This affects all organizations using vulnerable version...