← Vulnerability feed

Vulnerability record · CVE-2020-10631 · published 9 April 2020

CVE-2020-10631: Advantech webaccess\/nms relative path traversal vulnerability

Advantech · Webaccess\/Nms

An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control.

9.8 CVSS 3.1 Critical EPSS 1.5% · top 27.0% CWE-23 · Relative path traversalCWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 7.5
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.us-cert.gov/ics/advisories/icsa-20-098-01 Third Party AdvisoryUS Government Resource
https://www.us-cert.gov/ics/advisories/icsa-20-098-01 Third Party AdvisoryUS Government Resource

Track CVE-2020-10631 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10625Advantech webaccess\/nms missing authentication for critical function vulnerabilityWebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account.EPSS 1.6%9.8CVE-2020-10621Advantech webaccess\/nms unrestricted file upload vulnerabilityMultiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).EPSS 1.6%9.8CVE-2018-10589Advantech webaccess path traversal vulnerabilityIn Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…EPSS 4.0%9.8CVE-2018-7497Advantech webaccess null pointer dereference vulnerabilityIn Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…EPSS 2.8%9.8CVE-2018-7499Advantech webaccess stack-based buffer overflow vulnerabilityIn Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…EPSS 3.7%9.8CVE-2018-7505Advantech webaccess permissions and access controls vulnerabilityIn Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…EPSS 2.8%9.8CVE-2018-8845Advantech webaccess heap-based buffer overflow vulnerabilityIn Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…EPSS 5.6%9.1CVE-2020-10619Advantech webaccess\/nms relative path traversal vulnerabilityAn attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2020-10631), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.