First published: Thu Oct 27 2022(Updated: )
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech R-SeeNet | <=2.4.17 | |
Advantech Version 2.4.19 and prior | ||
Advantech Version 2.4.17 and prior (CVE-2022-3386 and CVE-2022-3385 only) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-3386.
The severity of CVE-2022-3386 is critical with a CVSS score of 9.8.
Advantech R-SeeNet versions 2.4.17 and prior are affected by CVE-2022-3386.
An unauthorized attacker can use an oversized filename to overflow the stack buffer and enable remote code execution.
It is recommended to update Advantech R-SeeNet to a version higher than 2.4.17 to mitigate CVE-2022-3386.