Advantech WebAccess
Advantech WebAccess contains multiple vulnerabilities including SQL injection (CWE-89), insecure file operations (CWE-548, CWE-22), insufficient access controls (CWE-285), and buffer overflow issues (CWE-121, CWE-122). Successful exploitation could allow an attacker to disclose sensitive information from the host and target systems, execute arbitrary code, or delete files. Affected versions: WebAccess <= 8.3.0, WebAccess <= 8.2_20170817, WebAccess/NMS <= 2.0.3, WebAccess Dashboard <= 2.0.15, and WebAccess Scada Node < 8.3.1.
- Network access to WebAccess server port (default port varies by deployment)
- No credentials required
- No specific configuration required for exploitation
Patching may require device reboot — plan for process interruption
/api/v1/advisories/ca701599-6941-4631-9b94-dafff70a9a38Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.