CVE-2019-10989: Advantech Webaccess

Critical severity, CVSS 9.8. EPSS: 8.6% chance of exploitation in the next 30 days.

In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution. Note: A different vulnerability than CVE-2019-10991.

Affected products

  • Advantech Webaccess: up to and including 8.3.5

Published 2019-06-28. Last modified 2026-06-17.