CVE-2014-2364 Information

Description

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName (2) SetParameter (3) NodeName (4) CCDParameter (5) SetColor (6) AlarmImage (7) GetParameter (8) GetColor (9) ServerResponse (10) SetBaud or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx (b) dvs.ocx or (c) webdact.ocx.

Reference

http://ics-cert.us-cert.gov/advisories/ICSA-14-198-02 http://packetstormsecurity.com/files/128384/Advantech-WebAccess-dvs.ocx-GetColor-Buffer-Overflow.html http://www.securityfocus.com/bid/68714

Share on: