PT-2018-14263 · Advantech · Webaccess

Mat Powell

·

Publicado

2018-10-29

·

Atualizado

2019-10-09

·

CVE-2018-17910

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Advantech WebAccess versions 8.3.2 and prior
Description The issue arises from the application's failure to properly validate the length of user-supplied data, leading to a buffer overflow condition. This condition allows for arbitrary remote code execution.
Recommendations For versions 8.3.2 and prior, update to a version that properly validates user-supplied data length to prevent buffer overflow conditions.

Correção

RCE

Stack Overflow

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-17910
ZDI-18-1330

Produtos afetados

Webaccess