Advantech WebAccess
Advantech WebAccess versions 8.4.1 and earlier contain multiple vulnerabilities (CWE-94, CWE-77, CWE-121, CWE-285) that allow unauthenticated remote attackers to execute arbitrary code with system-level privileges, access sensitive files, and delete data. Successful exploitation could allow attackers to modify control parameters, disrupt plant operations, or steal operational data. No known public exploits currently exist, but the vulnerabilities are easily discoverable and exploitable over the network.
- Network access to WebAccess server (HTTP/HTTPS port)
- No authentication required
- No user interaction needed
Patching may require device reboot — plan for process interruption
/api/v1/advisories/b39291b0-fd8b-441b-b124-8effd037d40eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.