PT-2018-14263 · Advantech · Webaccess
Mat Powell
·
Published
2018-10-29
·
Updated
2019-10-09
·
CVE-2018-17910
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Advantech WebAccess versions 8.3.2 and prior
Description
The issue arises from the application's failure to properly validate the length of user-supplied data, leading to a buffer overflow condition. This condition allows for arbitrary remote code execution.
Recommendations
For versions 8.3.2 and prior, update to a version that properly validates user-supplied data length to prevent buffer overflow conditions.
Fix
RCE
Stack Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webaccess