CVE-2018-8837: High severity Advantech WebAccess HMI Designer vulnerability
Published Apr 25, 2018
·Updated
Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.
Affected Software
1 affected component
Advantech WebAccess HMI Designer<=2.1.7.32
Event History
Apr 25, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-8837?
CVE-2018-8837 is a vulnerability in Advantech WebAccess HMI Designer 2.1.7.32 and prior that allows remote code execution.
2
How severe is CVE-2018-8837?
CVE-2018-8837 has a severity score of 7.8 (high).
3
How does CVE-2018-8837 occur?
CVE-2018-8837 occurs when processing specially crafted .pm3 files in Advantech WebAccess HMI Designer.
4
Which software versions are affected by CVE-2018-8837?
Advantech WebAccess HMI Designer versions up to and including 2.1.7.32 are affected by CVE-2018-8837.
5
How can CVE-2018-8837 be fixed?
To fix CVE-2018-8837, update Advantech WebAccess HMI Designer to a version beyond 2.1.7.32.