HIGH🇵🇱 Wersja polska

CVE-2014-2364

CVSS 7.5v2.0pub. 2014-07-19upd. 2026-05-06

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.

CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Advantech Webaccess

    APP
    Advantech
    5.06.07.0≤ 7.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2014-2368HIGH7.5same product

The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attack...

CVE-2014-2367HIGH7.5same product

The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess before ...

CVE-2014-2366HIGH9.0same product

upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by r...

CVE-2014-0766HIGH7.5same product

An attacker can exploit this vulnerability by copying an overly long NodeName2 argument into a statically siz...

CVE-2014-0764HIGH7.5same product

By providing an overly long string to the NodeName parameter, an attacker may be able to overflow the static ...