Known vulnerabilities in WebAccess Scada Node

Software CPE: cpe:2.3:a:advantech:webaccess_scada_node:*:*:*:*:*:*:*:*
Total vulnerabilities: 16
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting WebAccess Scada Node WebAccess Scada Node is affected by 16 known vulnerabilities: 6 high, 10 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU46825 - Permissions, Privileges, and Access Controls
CVE-2020-16202
CWE-264 Low
No
No
9.0.1 21.09.2020 SB2020092102
#VU28931 - Stack-based buffer overflow
CVE-2020-12019
CWE-121 High
No
No
8.4.4.P0520844 10.06.2020 SB2020061028
#VU17220 - Authentication Bypass Using an Alternate Path or Channel
CVE-2019-6521
CWE-288 Low
No
No
- 25.01.2019 SB2019012511
#VU17219 - Improper Authentication
CVE-2019-6519
CWE-287 Low
No
No
- 25.01.2019 SB2019012511
#VU17218 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-6523
CWE-89 Low
No
No
- 24.01.2019 SB2019012511
#VU12759 - Improper Privilege Management
CVE-2018-8841
CWE-269 Low
No
No
- 16.05.2018 SB2018051607
#VU12758 - Origin Validation Error
CVE-2018-10591
CWE-346 Low
No
No
- 16.05.2018 SB2018051607
#VU12757 - External Control of File Name or Path
CVE-2018-7495
CWE-73 Low
No
No
- 16.05.2018 SB2018051607
#VU12756 - Untrusted Pointer Dereference
CVE-2018-7497
CWE-822 High
No
No
- 16.05.2018 SB2018051607
#VU12755 - Heap-based Buffer Overflow
CVE-2018-8845
CWE-122 High
No
No
- 16.05.2018 SB2018051607
#VU12754 - Stack-based buffer overflow
CVE-2018-7499
CWE-121 High
No
No
- 16.05.2018 SB2018051607
#VU12753 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-10589
CWE-22 High
No
No
- 16.05.2018 SB2018051607
#VU12752 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-7503
CWE-22 Low
No
No
- 16.05.2018 SB2018051607
#VU12751 - Improper Authorization
CVE-2018-7505
CWE-285 High
No
No
- 16.05.2018 SB2018051607
#VU12750 - Exposure of sensitive information to an unauthorized actor
CVE-2018-10590
CWE-200 Low
No
No
- 16.05.2018 SB2018051607
#VU12749 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-7501
CWE-89 Low
No
No
- 15.05.2018 SB2018051607