CVE-2018-10591: Advantech Webaccess

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin validation error vulnerability has been identified, which may allow an attacker can create a malicious web site, steal session cookies, and access data of authenticated users.

Affected products

  • Advantech Webaccess: up to and including 8.2_20170817; up to and including 8.3.0
  • Advantech Webaccess/nms: up to and including 2.0.3
  • Advantech Webaccess Dashboard: up to and including 2.0.15
  • Advantech Webaccess Scada: before 8.3.1 (fixed in 8.3.1)

Published 2018-05-15. Last modified 2026-06-17.