PatchSiren cyber security CVE debrief
CVE-2025-14850 Advantech CVE debrief
A directory traversal vulnerability in Advantech WebAccess/SCADA allows authenticated attackers to delete arbitrary files on affected systems. The vulnerability carries a HIGH severity CVSS 3.1 score of 8.1, reflecting significant integrity and availability impact with low attack complexity. CISA published this advisory on December 18, 2025, as ICSA-25-352-06. The issue is not currently listed in CISA's Known Exploited Vulnerabilities catalog. Advantech has released version 9.2.2 to address this vulnerability. Organizations should prioritize patching, especially for internet-facing SCADA installations, and implement network segmentation to limit exposure of critical industrial control systems.
- Vendor
- Advantech
- Product
- WebAccess/SCADA
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-18
- Original CVE updated
- 2025-12-18
- Advisory published
- 2025-12-18
- Advisory updated
- 2025-12-18
Who should care
Organizations operating Advantech WebAccess/SCADA for industrial process control, particularly those with externally accessible management interfaces. Critical infrastructure operators in manufacturing, energy, water treatment, and building automation using this SCADA platform should prioritize assessment and patching.
Technical summary
The vulnerability exists in Advantech WebAccess/SCADA and stems from improper path validation, allowing directory traversal sequences to bypass intended file access restrictions. An attacker with low privileges can exploit this to delete arbitrary files on the underlying system. The CVSS 3.1 score of 8.1 reflects high integrity and availability impact with network accessibility and low attack complexity. No confidentiality impact is indicated. The attack requires no user interaction and maintains unchanged scope.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade to Advantech WebAccess/SCADA version 9.2.2 or later to remediate the directory traversal vulnerability
- Restrict network access to WebAccess/SCADA management interfaces, especially from untrusted networks
- Implement network segmentation to isolate SCADA systems from enterprise IT networks
- Monitor for unauthorized file deletion activity in WebAccess/SCADA installation directories
- Apply principle of least privilege to WebAccess/SCADA user accounts
- Review and validate backup integrity for critical SCADA configuration and runtime files
Evidence notes
CISA's advisory confirms the vulnerability type as directory traversal with arbitrary file deletion impact. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) indicates network attack vector, low complexity, low privileges required, and high impact to integrity and availability. Advantech's remediation guidance specifies WebAccess/SCADA version 9.2.2 as the fixed version.
Official resources
-
CVE-2025-14850 CVE record
CVE.org
-
CVE-2025-14850 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
CISA published advisory ICSA-25-352-06 on December 18, 2025, disclosing this vulnerability in Advantech WebAccess/SCADA. The advisory confirms active vendor coordination and availability of a patched version.