« Back to list

Advantech

Advantech Webaccess Scada: vulnerabilities and CVEs

Advantech Webaccess Scada has 14 published vulnerabilities, 1 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.

CVEs14
Last 12 months1
Critical5
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-36226Medium (6.1)0.30%—May 22, 2026
Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component
CVE-2024-2453Medium (6.4)0.30%—Mar 21, 2024
There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow…
CVE-2021-38431Medium (4.3)0.70%—Oct 15, 2021
An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.
CVE-2018-8845Critical (9.8)5.6%—May 15, 2018
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and…
CVE-2018-8841High (7.8)0.36%—May 15, 2018
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and…
CVE-2018-7505Critical (9.8)2.8%—May 15, 2018
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and…
CVE-2018-7503High (7.5)2.5%—May 15, 2018
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and…
CVE-2018-7501High (7.5)1.6%—May 15, 2018
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and…
CVE-2018-7499Critical (9.8)3.7%—May 15, 2018
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and…
CVE-2018-7497Critical (9.8)2.8%—May 15, 2018
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and…
CVE-2018-7495High (7.5)2.2%—May 15, 2018
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and…
CVE-2018-10591Medium (6.1)0.63%—May 15, 2018
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and…
CVE-2018-10590High (7.5)1.7%—May 15, 2018
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and…
CVE-2018-10589Critical (9.8)4.0%—May 15, 2018
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1083 File and Directory Discovery1
  2. T1190 Exploit Public-Facing Application1
  3. T1202 Indirect Command Execution1
  4. T1499.004 Application or System Exploitation1
  5. T1574 Hijack Execution Flow1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Advantech