Filtered by vendor Advantech
Subscriptions
Total
296 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-22674 | 1 Advantech | 1 Webaccess\/scada | 2024-08-03 | 6.5 Medium |
The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1). | ||||
CVE-2021-22667 | 1 Advantech | 2 Bb-eswgp506-2sfp-t, Bb-eswgp506-2sfp-t Firmware | 2024-08-03 | 9.8 Critical |
BB-ESWGP506-2SFP-T versions 1.01.09 and prior is vulnerable due to the use of hard-coded credentials, which may allow an attacker to gain unauthorized access and permit the execution of arbitrary code on the BB-ESWGP506-2SFP-T (versions 1.01.01 and prior). | ||||
CVE-2021-22658 | 1 Advantech | 1 Iview | 2024-08-03 | 9.8 Critical |
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'. | ||||
CVE-2021-22654 | 1 Advantech | 1 Iview | 2024-08-03 | 7.5 High |
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information. | ||||
CVE-2021-22656 | 1 Advantech | 1 Iview | 2024-08-03 | 7.5 High |
Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files. | ||||
CVE-2021-21937 | 1 Advantech | 1 R-seenet | 2024-08-03 | 6.5 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_alt_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery. | ||||
CVE-2021-21933 | 1 Advantech | 1 R-seenet | 2024-08-03 | 6.5 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘esn_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery. | ||||
CVE-2021-21915 | 1 Advantech | 1 R-seenet | 2024-08-03 | 8.8 High |
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery. | ||||
CVE-2021-21930 | 1 Advantech | 1 R-seenet | 2024-08-03 | 6.5 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery. | ||||
CVE-2021-21936 | 1 Advantech | 1 R-seenet | 2024-08-03 | 8.8 High |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘health_alt_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery. | ||||
CVE-2021-21925 | 1 Advantech | 1 R-seenet | 2024-08-03 | 6.5 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘firm_filter’ parameter. | ||||
CVE-2021-21924 | 1 Advantech | 1 R-seenet | 2024-08-03 | 6.5 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘desc_filter’ parameter. | ||||
CVE-2021-21926 | 1 Advantech | 1 R-seenet | 2024-08-03 | 6.5 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘health_filter’ parameter. | ||||
CVE-2021-21918 | 1 Advantech | 1 R-seenet | 2024-08-03 | 4.9 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without cross-site request forgery attack. | ||||
CVE-2021-21921 | 1 Advantech | 1 R-seenet | 2024-08-03 | 4.9 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter with the administrative account or through cross-site request forgery. | ||||
CVE-2021-21934 | 1 Advantech | 1 R-seenet | 2024-08-03 | 6.5 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘imei_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery. | ||||
CVE-2021-21932 | 1 Advantech | 1 R-seenet | 2024-08-03 | 6.5 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘name_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery. | ||||
CVE-2021-21927 | 1 Advantech | 1 R-seenet | 2024-08-03 | 6.5 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘loc_filter’ parameter. | ||||
CVE-2021-21931 | 1 Advantech | 1 R-seenet | 2024-08-03 | 6.5 Medium |
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery. | ||||
CVE-2021-21916 | 1 Advantech | 1 R-seenet | 2024-08-03 | 8.8 High |
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at 'description_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery. |