PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-14850 Advantech CVE debrief

A directory traversal vulnerability in Advantech WebAccess/SCADA allows authenticated attackers to delete arbitrary files on affected systems. The vulnerability carries a HIGH severity CVSS 3.1 score of 8.1, reflecting significant integrity and availability impact with low attack complexity. CISA published this advisory on December 18, 2025, as ICSA-25-352-06. The issue is not currently listed in CISA's Known Exploited Vulnerabilities catalog. Advantech has released version 9.2.2 to address this vulnerability. Organizations should prioritize patching, especially for internet-facing SCADA installations, and implement network segmentation to limit exposure of critical industrial control systems.

Vendor
Advantech
Product
WebAccess/SCADA
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2025-12-18
Original CVE updated
2025-12-18
Advisory published
2025-12-18
Advisory updated
2025-12-18

Who should care

Organizations operating Advantech WebAccess/SCADA for industrial process control, particularly those with externally accessible management interfaces. Critical infrastructure operators in manufacturing, energy, water treatment, and building automation using this SCADA platform should prioritize assessment and patching.

Technical summary

The vulnerability exists in Advantech WebAccess/SCADA and stems from improper path validation, allowing directory traversal sequences to bypass intended file access restrictions. An attacker with low privileges can exploit this to delete arbitrary files on the underlying system. The CVSS 3.1 score of 8.1 reflects high integrity and availability impact with network accessibility and low attack complexity. No confidentiality impact is indicated. The attack requires no user interaction and maintains unchanged scope.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade to Advantech WebAccess/SCADA version 9.2.2 or later to remediate the directory traversal vulnerability
  • Restrict network access to WebAccess/SCADA management interfaces, especially from untrusted networks
  • Implement network segmentation to isolate SCADA systems from enterprise IT networks
  • Monitor for unauthorized file deletion activity in WebAccess/SCADA installation directories
  • Apply principle of least privilege to WebAccess/SCADA user accounts
  • Review and validate backup integrity for critical SCADA configuration and runtime files

Evidence notes

CISA's advisory confirms the vulnerability type as directory traversal with arbitrary file deletion impact. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) indicates network attack vector, low complexity, low privileges required, and high impact to integrity and availability. Advantech's remediation guidance specifies WebAccess/SCADA version 9.2.2 as the fixed version.

Official resources

CISA published advisory ICSA-25-352-06 on December 18, 2025, disclosing this vulnerability in Advantech WebAccess/SCADA. The advisory confirms active vendor coordination and availability of a patched version.