PT-2020-14814 · Advantech · Advantech Webaccess Hmi Designer
Natnael Samson
+1
·
Published
2020-08-06
·
Updated
2021-11-22
·
CVE-2020-16215
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Advantech WebAccess HMI Designer versions 2.1.9.31 and prior
Description
The issue arises from processing specially crafted project files that lack proper validation of user-supplied data, leading to a stack-based buffer overflow. This may result in remote code execution, disclosure or modification of information, or cause the application to crash.
Recommendations
For Advantech WebAccess HMI Designer versions 2.1.9.31 and prior, update to a version later than 2.1.9.31 to resolve the issue. As a temporary workaround, consider restricting the processing of project files from untrusted sources to minimize the risk of exploitation.
Fix
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Advantech Webaccess Hmi Designer