CVE-2021-34540
MEDIUMCVSS 6.1/10EPSS 0.87%
Last modified
CVE-2021-34540 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Advantech | Webaccess | 8.4.2 |
| Advantech | Webaccess | 8.4.4 |
References
- https://github.com/ethancsyang/CveProject/tree/main/CVE-2021-34540Exploit, Third Party Advisory
- https://www.advantech.com/supportVendor Advisory
- https://github.com/ethancsyang/CveProject/tree/main/CVE-2021-34540Exploit, Third Party Advisory
- https://www.advantech.com/supportVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-34540?
Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.
How severe is CVE-2021-34540?
CVE-2021-34540 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 0.87% probability of exploitation in the next 30 days.
How do I fix CVE-2021-34540?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-34535Remote Desktop Client Remote Code Execution Vulnerability8.8
- CVE-2021-34536Windows Storage Spaces Controller Elevation of Privilege Vul…7.8
- CVE-2021-34537Windows Bluetooth Driver Elevation of Privilege Vulnerabilit…7.8
- CVE-2021-34538Apache Hive before 3.1.3 "CREATE" and "DROP" function operat…7.5
- CVE-2021-34539An issue was discovered in CubeCoders AMP before 2.1.1.8. A …7.2
- CVE-2021-3454Truncated L2CAP K-frame causes assertion failure. Zephyr ver…7.5
- CVE-2021-34543The web administration server in Solar-Log 500 before 2.8.2 …7.5
- CVE-2021-34544An issue was discovered in Solar-Log 500 before 2.8.2 Build …6.5
- CVE-2021-34546An unauthenticated attacker with physical access to a comput…6.8
- CVE-2021-34547PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF …4.3
- CVE-2021-34548An issue was discovered in Tor before 0.4.6.5, aka TROVE-202…7.5
- CVE-2021-34549An issue was discovered in Tor before 0.4.6.5, aka TROVE-202…7.5
Are you affected by CVE-2021-34540?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
