CVE-2019-16899: High severity advantech webaccess/hmi designer vulnerability
Published Sep 26, 2019
·Updated
In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starting at PMV3!CTagInfoThreadBase::GetNICInfo+0x0000000000512918.
Affected Software
1 affected component
Advantech Webaccess\/hmi Designer=2.1.9.31
Event History
Sep 26, 2019
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is CVE-2019-16899?
CVE-2019-16899 is a vulnerability in Advantech WebAccess/HMI Designer 2.1.9.31 that allows an attacker to control the code flow by exploiting data from a faulting address.
2
What is the severity of CVE-2019-16899?
CVE-2019-16899 has a severity rating of 7.5, which is considered high.
3
How does CVE-2019-16899 affect Advantech WebAccess/HMI Designer?
CVE-2019-16899 affects Advantech WebAccess/HMI Designer version 2.1.9.31.
4
How can the CVE-2019-16899 vulnerability be exploited?
The CVE-2019-16899 vulnerability can be exploited by using data from a faulting address to control the code flow.
5
Is there a fix available for CVE-2019-16899?
To mitigate the CVE-2019-16899 vulnerability, it is recommended to update to a patched version of Advantech WebAccess/HMI Designer.