Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/103972 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-18-114-03 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/103972 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-18-114-03 | Third Party Advisory US Government Resource |
Configurations
History
21 Nov 2024, 04:14
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/103972 - Third Party Advisory, VDB Entry | |
References | () https://ics-cert.us-cert.gov/advisories/ICSA-18-114-03 - Third Party Advisory, US Government Resource |
Information
Published : 2018-04-25 23:29
Updated : 2024-11-21 04:14
NVD link : CVE-2018-8837
Mitre link : CVE-2018-8837
CVE.ORG link : CVE-2018-8837
JSON object : View
Products Affected
advantech
- webaccess_hmi_designer
CWE
CWE-787
Out-of-bounds Write