ID

VAR-202011-1554


TITLE

Advantech WebAccess HMI PanelSim.exe has integer overflow vulnerability

Trust: 0.6

sources: CNVD: CNVD-2020-61117

DESCRIPTION

Advantech WebAccess/HMI Designer is a man-machine interface integrated development tool. Advantech's WebAccess HMI PanelSim.exe has an integer overflow vulnerability. Attackers can use the vulnerability to cause an integer overflow and cause the program to crash.

Trust: 0.6

sources: CNVD: CNVD-2020-61117

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-61117

AFFECTED PRODUCTS

vendor:advantechmodel:webaccess hmi runtimescope:eqversion:2.1.9.31

Trust: 0.6

sources: CNVD: CNVD-2020-61117

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-61117
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2020-61117
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-61117

EXTERNAL IDS

db:CNVDid:CNVD-2020-61117

Trust: 0.6

sources: CNVD: CNVD-2020-61117

SOURCES

db:CNVDid:CNVD-2020-61117

LAST UPDATE DATE

2022-05-04T09:55:26.519000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-61117date:2020-11-09T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-61117date:2020-11-09T00:00:00