First published: Thu Jun 24 2021(Updated: )
Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction is require on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess/HMI Designer | ||
Advantech WebAccess/HMI Designer | <=2.1.9.95 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-33002.
The severity of CVE-2021-33002 is high with a CVSS score of 7.8.
CVE-2021-33002 occurs by opening a maliciously crafted project file, which triggers an out-of-bounds write vulnerability.
An attacker can exploit CVE-2021-33002 by crafting a malicious project file and tricking a user into opening it, which may allow the attacker to execute arbitrary code.
The WebAccess HMI Designer versions 2.1.9.95 and prior are affected by CVE-2021-33002.