{"api_version":"1","generated_at":"2026-07-23T10:42:29+00:00","cve":"CVE-2017-16728","urls":{"html":"https://cve.report/CVE-2017-16728","api":"https://cve.report/api/cve/CVE-2017-16728.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-16728","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-16728"},"summary":{"title":"CVE-2017-16728","description":"An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the program to use an invalid memory address, resulting in a program crash.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2018-01-05 08:29:00","updated_at":"2019-10-09 23:25:00"},"problem_types":["CWE-476"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/102424","name":"102424","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-004-02","name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-004-02","refsource":"MISC","tags":["Broken Link","Third Party Advisory","US Government Resource"],"title":"Advantech WebAccess (Update A) | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-16728","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-16728","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"16728","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"advantech","cpe5":"webaccess","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"16728","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"advantech","cpe5":"webaccess","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-16728","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Advantech WebAccess","version":{"version_data":[{"version_value":"Advantech WebAccess"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the program to use an invalid memory address, resulting in a program crash."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-822"}]}]},"references":{"reference_data":[{"name":"102424","refsource":"BID","url":"http://www.securityfocus.com/bid/102424"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-004-02","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-004-02"}]}},"nvd":{"publishedDate":"2018-01-05 08:29:00","lastModifiedDate":"2019-10-09 23:25:00","problem_types":["CWE-476"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:advantech:webaccess:*:*:*:*:*:*:*:*","versionEndExcluding":"8.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"16728","Ordinal":"114474","Title":"CVE-2017-16728","CVE":"CVE-2017-16728","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"16728","Ordinal":"1","NoteData":"An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the program to use an invalid memory address, resulting in a program crash.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"16728","Ordinal":"2","NoteData":"2018-01-05","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"16728","Ordinal":"3","NoteData":"2018-01-06","Type":"Other","Title":"Modified"}]}}}