Heap-Based Buffer Overflow Vulnerabilities in Advantech WebAccess HMI Designer
CVE-2020-16207

7.8HIGH

Key Information:

Vendor
Advantech
Vendor
CVE Published:
6 August 2020

Summary

Advantech WebAccess HMI Designer versions 2.1.9.31 and earlier are susceptible to multiple heap-based buffer overflow vulnerabilities. These vulnerabilities can be triggered by opening specially crafted project files, potentially leading to serious consequences such as remote code execution, unauthorized information disclosure or modification, and application crashes. It is crucial for users of this software to address these vulnerabilities promptly to mitigate the risks associated with potential exploitation.

Affected Version(s)

Advantech WebAccess HMI Designer Versions 2.1.9.31 and prior

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.