CVE-2014-2364: Advantech WebAccess Stack-Based Buffer Overflow
Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2364?
CVE-2014-2364 has been rated with a high severity due to the potential for remote code execution.
How do I fix CVE-2014-2364?
To mitigate CVE-2014-2364, upgrade Advantech WebAccess to version 7.2 or later.
Which versions of Advantech WebAccess are affected by CVE-2014-2364?
CVE-2014-2364 affects Advantech WebAccess versions up to and including 7.1, as well as versions 5.0, 6.0, and 7.0.
Can CVE-2014-2364 be exploited remotely?
Yes, CVE-2014-2364 can be exploited remotely by sending specially crafted data to the affected application.
What types of attacks can result from CVE-2014-2364?
CVE-2014-2364 can lead to arbitrary code execution on the affected system, allowing attackers to potentially gain unauthorized access.