CVE-2017-12706: Buffer Overflow
A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.220170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12706?
CVE-2017-12706 has a high severity due to the risk of stack-based buffer overflow.
How do I fix CVE-2017-12706?
To address CVE-2017-12706, you should upgrade Advantech WebAccess to version 8.2_20170817 or later.
What versions of Advantech WebAccess are affected by CVE-2017-12706?
All versions of Advantech WebAccess prior to version 8.2_20170817 are affected by CVE-2017-12706.
What can happen if CVE-2017-12706 is exploited?
Exploitation of CVE-2017-12706 may allow an attacker to execute arbitrary code on the affected system.
Is CVE-2017-12706 related to user input validation?
Yes, CVE-2017-12706 is caused by insufficient validation of user-supplied data prior to it being copied to a stack-based buffer.