PT-2022-6036 · Advantech · Advantech R-Seenet

Rgod

·

Published

2022-10-18

·

Updated

2022-10-28

·

CVE-2022-3385

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech R-SeeNet versions 2.4.17 and prior
Description The issue is related to a stack-based buffer overflow in Advantech R-SeeNet. This can be exploited by an unauthorized attacker to remotely overflow the stack buffer, enabling remote code execution.
Recommendations For versions 2.4.17 and prior, update to a version later than 2.4.17 to resolve the issue. As a temporary workaround, consider restricting access to the show code endpoint until a patch is available. Avoid using functions that may trigger the stack-based buffer overflow until the issue is resolved.

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2022-07500
CVE-2022-3385
ZDI-22-1451

Affected Products

Advantech R-Seenet