CVE-2021-33002: High severity advantech webaccess/hmi designer vulnerability
Published Jun 24, 2021
·Updated
Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction is require on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Affected Software
2 affected components
Advantech WebAccess HMI Designer Versions prior to 2.1.11.0
Advantech Webaccess\/hmi Designer<=2.1.9.95
Event History
Jun 24, 2021
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-33002.
2
What is the severity of CVE-2021-33002?
The severity of CVE-2021-33002 is high with a CVSS score of 7.8.
3
How does CVE-2021-33002 occur?
CVE-2021-33002 occurs by opening a maliciously crafted project file, which triggers an out-of-bounds write vulnerability.
4
How can an attacker exploit CVE-2021-33002?
An attacker can exploit CVE-2021-33002 by crafting a malicious project file and tricking a user into opening it, which may allow the attacker to execute arbitrary code.
5
Which software versions are affected by CVE-2021-33002?
The WebAccess HMI Designer versions 2.1.9.95 and prior are affected by CVE-2021-33002.