Remote Code Execution Vulnerability in Advantech WebAccess HMI Designer
CVE-2020-16213

7.8HIGH

Key Information:

Vendor
Advantech
Vendor
CVE Published:
6 August 2020

Summary

The Advantech WebAccess HMI Designer is susceptible to a vulnerability that allows remote attackers to exploit specially crafted project files. This flaw occurs due to improper validation of user-supplied data, potentially leading to unauthorized control over the system, disclosure of sensitive information, modification of stored data, or crashing of the application. It is crucial for users to update their systems to prevent exploitation by malicious actors.

Affected Version(s)

Advantech WebAccess HMI Designer Versions 2.1.9.31 and prior

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.