CVE-2014-0768

An attacker may pass an overly long value from the AccessCode2 argument to the control to overflow the static stack buffer. The attacker may then remotely execute arbitrary code.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:advantech:advantech_webaccess:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:advantech_webaccess:5.0:*:*:*:*:*:*:*
cpe:2.3:a:advantech:advantech_webaccess:6.0:*:*:*:*:*:*:*
cpe:2.3:a:advantech:advantech_webaccess:7.0:*:*:*:*:*:*:*

History

19 Sep 2025, 20:15

Type Values Removed Values Added
References
  • () http://webaccess.advantech.com/ -
  • () http://www.securityfocus.com/bid/66740 -
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-14-079-03 -
CWE CWE-121
Summary (en) Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode2 argument. (en) An attacker may pass an overly long value from the AccessCode2 argument to the control to overflow the static stack buffer. The attacker may then remotely execute arbitrary code.

21 Nov 2024, 02:02

Type Values Removed Values Added
References () http://ics-cert.us-cert.gov/advisories/ICSA-14-079-03 - Third Party Advisory, US Government Resource () http://ics-cert.us-cert.gov/advisories/ICSA-14-079-03 - Third Party Advisory, US Government Resource
References () http://www.securityfocus.com/bid/66732 - () http://www.securityfocus.com/bid/66732 -

Information

Published : 2014-04-12 04:37

Updated : 2025-09-19 20:15


NVD link : CVE-2014-0768

Mitre link : CVE-2014-0768

CVE.ORG link : CVE-2014-0768


JSON object : View

Products Affected

advantech

  • advantech_webaccess
CWE
CWE-121

Stack-based Buffer Overflow

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer