PT-2016-1122 · Advantech · Advantech Webaccess

Published

2016-01-15

·

Updated

2016-12-03

·

CVE-2016-0856

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Advantech WebAccess versions prior to 8.1
Description The issue is caused by multiple stack-based buffer overflows in Advantech WebAccess. Exploitation of these overflows may allow a remote attacker to execute arbitrary code. The overflows occur in various services and components, including datacore.exe and webvrpcs services, and involve functions such as strcpy, sprintf, and strcat, affecting parameters like Path, ProjectName, HostName, NodeName, TagName, WindowName, and Username.
Recommendations For Advantech WebAccess versions prior to 8.1, update to version 8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable services, such as datacore and webvrpcs, until a patch is applied. Avoid using vulnerable functions like strcpy() and sprintf() in the affected components until the issue is resolved. Restrict input to parameters like Path, ProjectName, HostName, NodeName, TagName, WindowName, and Username to minimize the risk of exploitation.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00381
CVE-2016-0856
ZDI-16-048
ZDI-16-049
ZDI-16-050
ZDI-16-051
ZDI-16-053
ZDI-16-054
ZDI-16-055
ZDI-16-056
ZDI-16-057
ZDI-16-059
ZDI-16-060
ZDI-16-061
ZDI-16-062
ZDI-16-063
ZDI-16-069
ZDI-16-070
ZDI-16-071
ZDI-16-072
ZDI-16-073
ZDI-16-075
ZDI-16-076
ZDI-16-077
ZDI-16-078
ZDI-16-079
ZDI-16-080
ZDI-16-081
ZDI-16-082
ZDI-16-083
ZDI-16-084
ZDI-16-085
ZDI-16-086
ZDI-16-087
ZDI-16-088
ZDI-16-089
ZDI-16-090
ZDI-16-091
ZDI-16-092
ZDI-16-093
ZDI-16-094
ZDI-16-095
ZDI-16-096
ZDI-16-097
ZDI-16-098
ZDI-16-099
ZDI-16-100
ZDI-16-101
ZDI-16-102
ZDI-16-103
ZDI-16-106
ZDI-16-108
ZDI-16-109
ZDI-16-110
ZDI-16-111
ZDI-16-112
ZDI-16-113
ZDI-16-114
ZDI-16-115
ZDI-16-116
ZDI-16-117
ZDI-16-118
ZDI-16-120

Affected Products

Advantech Webaccess