CVE-2022-3386: Buffer Overflow
Published Oct 27, 2022
·Updated
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.
Affected Software
3 affected components
Advantech R-SeeNet<=2.4.17
Advantech Version 2.4.19 and prior
Advantech Version 2.4.17 and prior (CVE-2022-3386 and CVE-2022-3385 only)
Event History
Oct 27, 2022
CVE Published
via MITRE·08:34 PM
Data Sourced
via MITRE·08:34 PM
DescriptionSeverityWeakness
Aug 3, 2024
Data Sourced
via ICS·01:17 AM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3386.
2
What is the severity of CVE-2022-3386?
The severity of CVE-2022-3386 is critical with a CVSS score of 9.8.
3
What is affected by CVE-2022-3386?
Advantech R-SeeNet versions 2.4.17 and prior are affected by CVE-2022-3386.
4
How does CVE-2022-3386 work?
An unauthorized attacker can use an oversized filename to overflow the stack buffer and enable remote code execution.
5
Is there a fix for CVE-2022-3386?
It is recommended to update Advantech R-SeeNet to a version higher than 2.4.17 to mitigate CVE-2022-3386.