Advantech WebAccess Stack-based Buffer Overflow
Summary
| CVE | CVE-2014-0770 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-04-12 04:37:31 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | By providing an overly long string to the UserName parameter, an attacker may be able to overflow the static stack buffer. The attacker may then execute code on the target device remotely. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: CWE-121 | CWE-119 | CWE-121 CWE-121
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | [email protected] | Secondary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | CNA | CVSS | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Advantech | Advantech Webaccess | 5.0 | All | All | All |
| Application | Advantech | Advantech Webaccess | 6.0 | All | All | All |
| Application | Advantech | Advantech Webaccess | 7.0 | All | All | All |
| Application | Advantech | Advantech Webaccess | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advantech WebAccess Vulnerabilities | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | US Government Resource |
| webaccess.advantech.com | [email protected] | webaccess.advantech.com | |
| www.securityfocus.com/bid/66740 | [email protected] | www.securityfocus.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-14-079-03 | [email protected] | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Andrea Micalizzi, aka rgod, Tom Gallagher, and an independent anonymous researcher working with HP’s Zero Day Initiative (ZDI) (en)
Additional Advisory Data
Solutions
CNA: Advantech has created a new version (Version 7.2) that mitigates each of the vulnerabilities described above. Users may download this version from the following location at their web site: http://webaccess.advantech.com/downloads.php?item=software For additional information about WebAccess, please visit the following Advantech web site: http://webaccess.advantech.com/
There are currently no legacy QID mappings associated with this CVE.