PT-2019-3565 · Advantech · Advantech Webaccess
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Advantech WebAccess versions 8.3.5 and prior
Description
The issue is related to multiple stack-based buffer overflow vulnerabilities in the webvrpcs process of Advantech WebAccess software. These vulnerabilities are caused by a lack of proper validation of the length of user-supplied data before it is copied into a fixed-length buffer. Exploitation of these vulnerabilities may allow a remote attacker to execute arbitrary code.
Recommendations
For versions 8.3.5 and prior, update to a version that includes the necessary security patches to fix the stack-based buffer overflow vulnerabilities.
As a temporary workaround, consider restricting access to the webvrpcs process and related components, such as
bwclient, BwPAlarm, bwscrp, bwmail, bwwebv, and viewsrv, to minimize the risk of exploitation.Correção
RCE
Stack Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Advantech Webaccess