There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-27402 There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.
Fixes

Solution

Advantech recommends updating WebAccess/SCADA to version 9.1.6 or higher to mitigate this vulnerability.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00086}

epss

{'score': 0.00067}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-01T19:11:53.526Z

Reserved: 2024-03-14T15:12:14.027Z

Link: CVE-2024-2453

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:53.526Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-21T23:15:11.400

Modified: 2024-11-21T09:09:47.157

Link: CVE-2024-2453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:45:13Z