First published: Fri May 08 2020(Updated: )
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess/SCADA | ||
Advantech WebAccess | <=8.4.4 | |
Advantech WebAccess | =9.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12002 is a vulnerability in Advantech WebAccess/SCADA that allows remote attackers to execute arbitrary code on affected installations.
CVE-2020-12002 has a severity score of 9.8 (Critical).
The affected software for CVE-2020-12002 includes Advantech WebAccess/SCADA versions up to 8.4.4 and version 9.0.0.
No, authentication is not required to exploit CVE-2020-12002.
To fix CVE-2020-12002, it is recommended to apply the necessary security patches or updates provided by Advantech.