PT-2016-1123 · Advantech · Webaccess
Publicado
2016-01-15
·
Atualizado
2016-12-03
·
CVE-2016-0857
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Advantech WebAccess versions prior to 8.1
Description
The issue is caused by multiple heap-based buffer overflows, allowing remote attackers to execute arbitrary code via unspecified vectors. This can be exploited by a remote attacker to gain control over the system. The vulnerability is related to the
strcpy function in various services, including datacore.exe and BwpAlarm.dll.Recommendations
For versions prior to 8.1, update to version 8.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
datacore.exe and BwpAlarm.dll services until a patch is available.
Avoid using the strcpy function in the affected services until the issue is resolved.Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Webaccess