← All CVEs

CVE-2014-2364

high · 7.5

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.

7.5
CVSS
61.4%
EPSS (exploit prob.)
99th
EPSS percentile
2014-07-19
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-121CWE-119

Affected products

VendorProductAffected versions
advantechadvantech_webaccess<= 7.1
advantechadvantech_webaccess5.0
advantechadvantech_webaccess6.0
advantechadvantech_webaccess7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-2364