Vulnerability Details CVE-2021-33002
Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction is require on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.2%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2021-33002
-
cpe:2.3:a:advantech:webaccess/hmi_designer:-
-
cpe:2.3:a:advantech:webaccess/hmi_designer:2.1
-
cpe:2.3:a:advantech:webaccess/hmi_designer:2.1.9.31
-
cpe:2.3:a:advantech:webaccess/hmi_designer:2.1.9.95