CVE-2016-0859: Buffer Overflow
Published Jan 15, 2016
·Updated
Integer overflow in the Kernel service in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted RPC request.
Affected Software
1 affected component
Advantech WebAccess<=8.0
Event History
Jan 15, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0859?
CVE-2016-0859 has a critical severity rating due to the potential for remote code execution and denial of service.
2
How do I fix CVE-2016-0859?
To fix CVE-2016-0859, upgrade Advantech WebAccess to version 8.1 or later.
3
What types of attacks can exploit CVE-2016-0859?
CVE-2016-0859 can be exploited through crafted RPC requests leading to arbitrary code execution or stack-based buffer overflow.
4
Which versions of Advantech WebAccess are affected by CVE-2016-0859?
Versions of Advantech WebAccess prior to 8.1, specifically up to 8.0, are affected by CVE-2016-0859.
5
Is there a risk of data loss with CVE-2016-0859?
Yes, exploitation of CVE-2016-0859 can lead to denial of service which might cause temporary data loss.