QID 590684
Date Published: 2022-03-03
QID 590684: Advantech WebAccess HMI Designer Multiple Vulnerabilities (ICSA-21-173-01)
AFFECTED PRODUCTS
The following versions of Advantech WebAccess HMI Designer are affected:
WebAccess HMI Designer Versions prior to 2.1.11.0
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
Successful exploitation of these vulnerabilities could result in memory corruption, code execution, hijacking of user cookie/session tokens, and unintended browser action.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-173-01 for affected packages and patching details.
Vendor References
- ICSA-21-173-01 -
www.cisa.gov/uscert/ics/advisories/icsa-21-173-01
CVEs related to QID 590684
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| icsa-21-173-01 |
|