PT-2018-14263 · Advantech · Webaccess

Mat Powell

·

Published

2018-10-29

·

Updated

2019-10-09

·

CVE-2018-17910

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Advantech WebAccess versions 8.3.2 and prior
Description The issue arises from the application's failure to properly validate the length of user-supplied data, leading to a buffer overflow condition. This condition allows for arbitrary remote code execution.
Recommendations For versions 8.3.2 and prior, update to a version that properly validates user-supplied data length to prevent buffer overflow conditions.

Fix

RCE

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17910
ZDI-18-1330

Affected Products

Webaccess