CVE-2014-0768: Advantech WebAccess Stack-based Buffer Overflow
An attacker may pass an overly long value from the AccessCode2 argument to the control to overflow the static stack buffer. The attacker may then remotely execute arbitrary code.
Other sources
Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode2 argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Advantech WebAccessto a version that resolves this vulnerability.Fixed in 7.2
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0768?
CVE-2014-0768 is considered to have a high severity rating due to the potential for remote code execution.
How do I fix CVE-2014-0768?
To fix CVE-2014-0768, upgrade Advantech WebAccess to version 7.2 or later.
What systems are affected by CVE-2014-0768?
CVE-2014-0768 affects Advantech WebAccess versions 5.0, 6.0, 7.0, and earlier than 7.2.
What type of vulnerability is CVE-2014-0768?
CVE-2014-0768 is a stack-based buffer overflow vulnerability.
Can CVE-2014-0768 be exploited remotely?
Yes, CVE-2014-0768 can be exploited remotely by attackers using a crafted long AccessCode2 argument.