QID 590536

Date Published: 2021-09-16

QID 590536: Advantech WebAccess Buffer Overflow Vulnerability (ICSA-20-086-01)

AFFECTED PRODUCTSThe following versions of WebAccess, an HMI platform, are affected:
WebAccess Versions 8.4.2 and prior

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys.

Successful exploitation of this vulnerability may allow remote code execution.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-20-086-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590536

    Software Advisories
    Advisory ID Software Component Link
    ICSA-20-086-01 URL Logo www.us-cert.gov/ics/advisories/ICSA-20-086-01