Vulnerability Details CVE-2014-2364
Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.614
EPSS Ranking 99.1%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2014-2364
-
cpe:2.3:a:advantech:advantech_webaccess:5.0
-
cpe:2.3:a:advantech:advantech_webaccess:6.0
-
cpe:2.3:a:advantech:advantech_webaccess:7.0