PatchSiren cyber security CVE debrief
CVE-2025-14850 Advantech CVE debrief
A directory traversal vulnerability in Advantech WebAccess/SCADA allows authenticated attackers to delete arbitrary files on affected systems. The vulnerability carries a HIGH severity CVSS 3.1 score of 8.1, reflecting significant integrity and availability impact with low attack complexity. CISA published this advisory on December 18, 2025, as ICSA-25-352-06. The issue is not currently listed in CISA's Known Exploited Vulnerabilities catalog. Advantech has released version 9.2.2 to address this vulnerability. Organizations should prioritize patching, especially for internet-facing SCADA installations, and implement network segmentation to limit exposure of critical industrial control systems.
- Vendor
- Advantech
- Product
- WebAccess/SCADA
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-18
- Original CVE updated
- 2025-12-18
- Advisory published
- 2025-12-18
- Advisory updated
- 2025-12-18
Who should care
Organizations operating Advantech WebAccess/SCADA for industrial process control, particularly those with externally accessible management interfaces. Critical infrastructure operators in manufacturing, energy, water treatment, and building automation using this SCADA platform should prioritize assessment and patching.
Technical summary
The vulnerability exists in Advantech WebAccess/SCADA and stems from improper path validation, allowing directory traversal sequences to bypass intended file access restrictions. An attacker with low privileges can exploit this to delete arbitrary files on the underlying system. The CVSS 3.1 score of 8.1 reflects high integrity and availability impact with network accessibility and low attack complexity. No confidentiality impact is indicated. The attack requires no user interaction and maintains unchanged scope.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade to Advantech WebAccess/SCADA version 9.2.2 or later to remediate the directory traversal vulnerability
- Restrict network access to WebAccess/SCADA management interfaces, especially from untrusted networks
- Implement network segmentation to isolate SCADA systems from enterprise IT networks
- Monitor for unauthorized file deletion activity in WebAccess/SCADA installation directories
- Apply principle of least privilege to WebAccess/SCADA user accounts
- Review and validate backup integrity for critical SCADA configuration and runtime files
Evidence notes
CISA's advisory confirms the vulnerability type as directory traversal with arbitrary file deletion impact. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) indicates network attack vector, low complexity, low privileges required, and high impact to integrity and availability. Advantech's remediation guidance specifies WebAccess/SCADA version 9.2.2 as the fixed version.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-14850 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-14850
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-14850 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14850
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-352-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.