PT-2021-20016 · Advantech · Advantech Webaccess Hmi Designer
Chizuru Toyama
+2
·
Published
2021-04-27
·
Updated
2022-07-02
·
CVE-2021-33004
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Advantech WebAccess HMI Designer versions 2.1.9.95 and prior
Description
The issue is related to a memory corruption condition due to the lack of proper validation of user-supplied files. This may allow an attacker to execute arbitrary code, but user interaction is required. The vulnerability is associated with the parsing of specific file types.
Recommendations
For Advantech WebAccess HMI Designer versions 2.1.9.95 and prior, consider restricting the use of the file parsing functionality until a patch is available. As a temporary workaround, avoid using the WebAccess HMI Designer to open or parse untrusted files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Advantech Webaccess Hmi Designer