CVE-2014-2364
high · 7.5Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.
7.5
CVSS
61.4%
EPSS (exploit prob.)
99th
EPSS percentile
2014-07-19
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
CWE-121CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| advantech | advantech_webaccess | <= 7.1 |
| advantech | advantech_webaccess | 5.0 |
| advantech | advantech_webaccess | 6.0 |
| advantech | advantech_webaccess | 7.0 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/128384/Advantech-WebAccess-dvs.ocx-GetColor-Buffer-Overflow.html
- http://webaccess.advantech.com/
- http://www.securityfocus.com/bid/68714
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-198-02
- http://ics-cert.us-cert.gov/advisories/ICSA-14-198-02
- http://packetstormsecurity.com/files/128384/Advantech-WebAccess-dvs.ocx-GetColor-Buffer-Overflow.html
- http://www.securityfocus.com/bid/68714
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-2364