CVE-2021-33000: Buffer Overflow
Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33000?
CVE-2021-33000 is a vulnerability that allows an attacker to perform arbitrary code execution by parsing a malicious project file on Advantech WebAccess HMI Designer versions 2.1.9.95 and prior.
What is the severity of CVE-2021-33000?
The severity of CVE-2021-33000 is high, with a CVSS score of 7.8 out of 10.
How does CVE-2021-33000 affect the Advantech WebAccess HMI Designer?
CVE-2021-33000 affects the Advantech WebAccess HMI Designer versions 2.1.9.95 and prior by allowing an attacker to perform arbitrary code execution through a heap-based buffer overflow triggered by parsing a malicious project file.
Is user interaction required for CVE-2021-33000 to be exploited?
Yes, user interaction is required on the WebAccess HMI Designer for CVE-2021-33000 to be exploited.
How can I mitigate the CVE-2021-33000 vulnerability?
To mitigate the CVE-2021-33000 vulnerability, it is recommended to update to a version of Advantech WebAccess HMI Designer that is not affected by the vulnerability.