First published: Tue Dec 17 2019(Updated: )
In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the user running DiagAnywhere Server.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech DiagAnywhere | <=3.07.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18257 is considered a critical severity vulnerability due to its potential for arbitrary code execution.
To mitigate CVE-2019-18257, upgrade Advantech DiagAnywhere Server to version 3.07.12 or later.
CVE-2019-18257 is associated with multiple stack-based buffer overflow vulnerabilities in the file transfer service.
CVE-2019-18257 impacts users of Advantech DiagAnywhere Server versions 3.07.11 and earlier.
Yes, CVE-2019-18257 can be exploited remotely by an unauthenticated attacker.