PT-2021-20016 · Advantech · Advantech Webaccess Hmi Designer

Chizuru Toyama

+2

·

Published

2021-04-27

·

Updated

2022-07-02

·

CVE-2021-33004

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech WebAccess HMI Designer versions 2.1.9.95 and prior
Description The issue is related to a memory corruption condition due to the lack of proper validation of user-supplied files. This may allow an attacker to execute arbitrary code, but user interaction is required. The vulnerability is associated with the parsing of specific file types.
Recommendations For Advantech WebAccess HMI Designer versions 2.1.9.95 and prior, consider restricting the use of the file parsing functionality until a patch is available. As a temporary workaround, avoid using the WebAccess HMI Designer to open or parse untrusted files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33004
ZDI-21-441
ZDI-21-442
ZDI-21-489

Affected Products

Advantech Webaccess Hmi Designer