V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-2364
CVE
HighConfirmedExploit available

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string …

CVSS
7.5
High
EPSS
0.61
p99
Published
2014-01-01
Updated
2014-01-01
Description

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.

Tags · CWE
CWE-121
Affected products
Advantech_webaccess ≤ 7.1Advantech_webaccess
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.614 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
34757
exploitdb · https://www.exploit-db.com/exploits/34757
Enterprise
Affected products
ProductVendorStatus
advantech_webaccess*Tracked
Source databases
CVE