First published: Thu Aug 06 2020(Updated: )
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech Webaccess\/hmi Designer | <=2.1.9.31 | |
Advantech WebAccess/HMI Designer | ||
Advantech WebAccess HMI Designer Versions 2.1.9.31 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-16213 is high with a score of 7.8.
Remote attackers can exploit CVE-2020-16213 by executing arbitrary code on affected installations of Advantech WebAccess/HMI Designer through user interaction, such as visiting a malicious page or opening a malicious file.
Advantech WebAccess/HMI Designer versions up to and including 2.1.9.31 are affected by CVE-2020-16213.
Yes, you can find more information about CVE-2020-16213 in the following references: [US-CERT Advisory](https://us-cert.cisa.gov/ics/advisories/icsa-20-219-02) and [ZDI Advisory](https://www.zerodayinitiative.com/advisories/ZDI-20-956/).
The Common Weakness Enumeration (CWE) ID for CVE-2020-16213 is 787.