Cross-Site Scripting Vulnerability in WebAccess/SCADA by Advantech
CVE-2021-27436

6.1MEDIUM

Key Information:

Vendor

Advantech

Vendor
CVE Published:
18 March 2021

What is CVE-2021-27436?

WebAccess/SCADA from Advantech is susceptible to cross-site scripting vulnerabilities, which enables attackers to inject malicious JavaScript into webpages viewed by users. This can lead to serious consequences, including the theft of session cookies or tokens, unwanted redirection to harmful sites, and execution of unsolicited commands in the user's browser. Organizations using affected versions of this software should take immediate action to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Advantech WebAccess/SCADA Versions 9.0 and prior

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.