← Back to browse · API

CVE-2023-1437

Severity
CRITICAL
CVSS
9.8
EPSS
0.02798
Risk score
40.18
CISA KEV
No
PoC
No
Published
2023-08-02
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2023-23687, GHSA-QV79-48VX-52FW
Products
Advantech:WebAccess/SCADA 0 <9.1.4
Sources
euvd EUVD-2023-23687

Description

All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.

References