Vulnerability Details CVE-2021-33000
Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.1%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2021-33000
-
cpe:2.3:a:advantech:webaccess/hmi_designer:-
-
cpe:2.3:a:advantech:webaccess/hmi_designer:2.1
-
cpe:2.3:a:advantech:webaccess/hmi_designer:2.1.9.31
-
cpe:2.3:a:advantech:webaccess/hmi_designer:2.1.9.95