In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution.
References
Link | Resource |
---|---|
https://www.us-cert.gov/ics/advisories/icsa-19-213-01 | Patch Third Party Advisory US Government Resource |
https://www.zerodayinitiative.com/advisories/ZDI-19-691/ | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2019-08-02 10:15
Updated : 2023-03-03 07:51
NVD link : CVE-2019-10961
Mitre link : CVE-2019-10961
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
advantech
- webaccess_hmi_designer