CVE-2019-3954: Buffer Overflow
Published Jun 18, 2019
·Updated
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 81024 RPC call.
Affected Software
1 affected component
Advantech WebAccess=8.4.0
Event History
Jun 18, 2019
CVE Published
via MITRE·11:16 PM
Data Sourced
via MITRE·11:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-3954?
CVE-2019-3954 is a stack-based buffer overflow vulnerability in Advantech WebAccess/SCADA 8.4.0.
2
How severe is CVE-2019-3954?
CVE-2019-3954 has a severity rating of critical, with a CVSS score of 9.8.
3
How does CVE-2019-3954 affect Advantech WebAccess?
CVE-2019-3954 affects Advantech WebAccess version 8.4.0.
4
What is the impact of CVE-2019-3954?
CVE-2019-3954 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 81024 RPC call.
5
Is there a fix for CVE-2019-3954?
At the time of this writing, there is no known fix for CVE-2019-3954. It is recommended to apply any available security patches or updates from the vendor.