CVE-2014-0770: Advantech WebAccess Stack-based Buffer Overflow
By providing an overly long string to the UserName parameter, an attacker may be able to overflow the static stack buffer. The attacker may then execute code on the target device remotely.
Other sources
Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long UserName parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Advantech WebAccessto a version that resolves this vulnerability.Fixed in 7.2
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0770?
CVE-2014-0770 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2014-0770?
To fix CVE-2014-0770, upgrade Advantech WebAccess to version 7.2 or later.
Which versions of Advantech WebAccess are affected by CVE-2014-0770?
CVE-2014-0770 affects Advantech WebAccess versions 5.0, 6.0, and 7.1 or earlier.
What type of vulnerability is CVE-2014-0770?
CVE-2014-0770 is a stack-based buffer overflow vulnerability.
Can CVE-2014-0770 be exploited remotely?
Yes, CVE-2014-0770 can be exploited remotely if the attacker sends a specially crafted UserName parameter.