PT-2019-3562 · Advantech · Advantech Webaccess

Natnael Samson

+1

·

Published

2019-06-27

·

Updated

2022-04-18

·

CVE-2019-10993

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech WebAccess versions 8.3.5 and prior
Description The issue is related to multiple untrusted pointer dereference vulnerabilities in the webvrpcs process of Advantech WebAccess software. These vulnerabilities may allow a remote attacker to execute arbitrary code. The vulnerabilities are associated with the lack of checking the value of a pointer before it is dereferenced.
Recommendations For Advantech WebAccess versions 8.3.5 and prior, update to a version later than 8.3.5 to resolve the issue. As a temporary workaround, consider restricting access to the viewsrv module to minimize the risk of exploitation. Avoid using the vulnerable functions, such as SQLAllocStmt, fClose, SQLExecute, SQLNumResultCols, SQLSetConnectOption, SQLAllocConnect, findClose, fWrite, SQLExecDirect, SQLParamData, SQLNumParams, rewind, SQLGetData, SQLFetch, SQLDisconnect, SQLDescribeParam, SQLConnect, SQLFreeStmt, fileno, ftell, SQLPrepare, SQLFreeConnect, SQLCancel, SQLSetStmtAttr, SQLSetParam, and SQLFreeEnv, until a patch is available.

Fix

Buffer Overflow

Untrusted Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03763
CVE-2019-10993
ZDI-19-593
ZDI-19-595
ZDI-19-596
ZDI-19-597
ZDI-19-598
ZDI-19-599
ZDI-19-600
ZDI-19-601
ZDI-19-602
ZDI-19-603
ZDI-19-604
ZDI-19-605
ZDI-19-606
ZDI-19-607
ZDI-19-608
ZDI-19-609
ZDI-19-610
ZDI-19-611
ZDI-19-612
ZDI-19-613
ZDI-19-614
ZDI-19-615
ZDI-19-616
ZDI-19-617
ZDI-19-618
ZDI-19-623

Affected Products

Advantech Webaccess