Remote Code Execution Vulnerability in Advantech WebAccess HMI Designer
CVE-2018-8837

7.8HIGH

Key Information:

Vendor

Ics-cert

Vendor
CVE Published:
25 April 2018

What is CVE-2018-8837?

A vulnerability in Advantech WebAccess HMI Designer allows remote code execution due to improper processing of specially crafted .pm3 files. This flaw may enable attackers to manipulate the memory and execute arbitrary code, potentially compromising the integrity and confidentiality of the system. Organizations using affected versions are advised to implement security measures and apply available updates to mitigate risks.

Affected Version(s)

Advantech WebAccess HMI Designer Advantech WebAccess HMI Designer, Version 2.1.7.32 and prior.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.