CVE-2020-12022

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An improper validation vulnerability exists that could allow an attacker to inject specially crafted input into memory where it can be executed.
References
Link Resource
https://www.us-cert.gov/ics/advisories/icsa-20-128-01 Third Party Advisory US Government Resource
https://www.zerodayinitiative.com/advisories/ZDI-20-598/ Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:advantech:webaccess:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:webaccess:9.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-05-08 12:15

Updated : 2024-02-28 17:47


NVD link : CVE-2020-12022

Mitre link : CVE-2020-12022

CVE.ORG link : CVE-2020-12022


JSON object : View

Products Affected

advantech

  • webaccess
CWE
CWE-129

Improper Validation of Array Index