Advantech WebAccess Stack-Based Buffer Overflow
Summary
| CVE | CVE-2014-2364 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-07-19 05:09:27 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: CWE-121 | CWE-119 | CWE-121 CWE-121
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | [email protected] | Secondary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | CNA | CVSS | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Advantech | Advantech Webaccess | 5.0 | All | All | All |
| Application | Advantech | Advantech Webaccess | 6.0 | All | All | All |
| Application | Advantech | Advantech Webaccess | 7.0 | All | All | All |
| Application | Advantech | Advantech Webaccess | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advantech WebAccess Vulnerabilities | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| Advantech WebAccess dvs.ocx GetColor Buffer Overflow ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit |
| www.cisa.gov/news-events/ics-advisories/icsa-14-198-02 | [email protected] | www.cisa.gov | |
| Advantech WebAccess CVE-2014-2364 Multiple Remote Stack Based Buffer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| webaccess.advantech.com | [email protected] | webaccess.advantech.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: reported to ZDI by security researchers Dave Weinstein, Tom Gallagher, John Leitch, and others (en)
Additional Advisory Data
Solutions
CNA: Advantech released a new WebAccess Installation Package v7.2 on June 6, 2014, that removes some vulnerable ActiveX components and resolves the vulnerabilities within others. The download link for v7.2 is available at: http://webaccess.advantech.com/
There are currently no legacy QID mappings associated with this CVE.