First published: Thu Jun 24 2021(Updated: )
The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech Webaccess\/hmi Designer | <=2.1.9.95 | |
Advantech WebAccess HMI Designer Versions prior to 2.1.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-33004.
CVE-2021-33004 has a severity rating of 7.8 (high).
The affected software for CVE-2021-33004 is Advantech WebAccess HMI Designer (versions 2.1.9.95 and prior).
CVE-2021-33004 can lead to memory corruption and allow an attacker to execute arbitrary code on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Yes, user interaction is required for CVE-2021-33004 to be exploited on the WebAccess HMI Designer (versions 2.1.9.95 and prior).