Advantech WebAccess Stack-Based Buffer Overflow
68Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 7.5epss 61%
from disclosure to weapon67 days
Published on NVDJul 19
1st PoC+67d
metasploitJul 17
exploitation probability
61%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
Advantech · WebAccesspublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/34757cve_referencepacketstormsecurity.com/files/128384/Advantech-WebAccess-dvs.ocx-GetColor-Buffer-Overflow.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.