Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/103972 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-18-114-03 | Third Party Advisory US Government Resource |
Configurations
History
No history.
Information
Published : 2018-04-25 23:29
Updated : 2019-10-09 23:42
NVD link : CVE-2018-8837
Mitre link : CVE-2018-8837
CVE.ORG link : CVE-2018-8837
JSON object : View
Products Affected
advantech
- webaccess_hmi_designer
CWE
CWE-787
Out-of-bounds Write