Advantech WebAccess/SCADA
is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.
Metrics
Affected Vendors & Products
References
History
Fri, 19 Dec 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Advantech
Advantech webaccess/scada |
|
| Vendors & Products |
Advantech
Advantech webaccess/scada |
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code. | |
| Title | Advantech WebAccess/SCADA Unrestricted Upload of File with Dangerous Type | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2025-12-18T20:32:38.746Z
Updated: 2025-12-18T21:46:46.491Z
Reserved: 2025-12-17T18:58:28.259Z
Link: CVE-2025-14849
Updated: 2025-12-18T21:02:52.221Z
Status : Awaiting Analysis
Published: 2025-12-18T21:15:52.743
Modified: 2025-12-19T18:00:18.330
Link: CVE-2025-14849
No data.