CVE-2023-1437: Advantech Webaccess/scada

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files.

Affected products

  • Advantech Webaccess/scada: before 9.1.4 (fixed in 9.1.4)

Published 2023-08-02. Last modified 2026-06-17.