PT-2019-3768 · Advantech · Advantech Webaccess

Mat Powell

·

Published

2019-01-29

·

Updated

2020-10-06

·

CVE-2019-6550

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech WebAccess versions 8.3.5 and prior
Description The issue is caused by a stack-based buffer overflow due to a lack of proper validation of the length of user-supplied data. This may allow a remote attacker to execute arbitrary code.
Recommendations For Advantech WebAccess versions 8.3.5 and prior, update to a version later than 8.3.5 to resolve the issue. At the moment, there is no information about additional mitigation measures.

Fix

RCE

Stack Overflow

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04028
CVE-2019-6550
ZDI-19-308
ZDI-19-309
ZDI-19-310
ZDI-19-311
ZDI-19-312
ZDI-19-313
ZDI-19-314
ZDI-19-315
ZDI-19-316
ZDI-19-317
ZDI-19-318
ZDI-19-319
ZDI-19-320
ZDI-19-321
ZDI-19-322
ZDI-19-323
ZDI-19-325
ZDI-19-327
ZDI-19-328
ZDI-19-329
ZDI-19-330
ZDI-19-585

Affected Products

Advantech Webaccess