Check Point Reference: | CPAI-2014-1841 |
Date Published: | 14 Oct 2014 |
Severity: | Medium |
Last Updated: | Tuesday 14 October, 2014 |
Source: | |
Industry Reference: | CVE-2014-0991 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Advantech WebAccess 7.2 prior to 3.4.3 |
Vulnerability Description | A stack buffer overflow exists in Advantech's WebAccess SCADA software. This is due to insufficient input validation of the ProjectName parameter contained in the webvact.ocx ActiveX control, a part of the WebAccess Client. A remote, unauthenticated attacker could exploit this vulnerability by enticing a vulnerable user to open a crafted web page. |
SmartView Tracker will log the following entries:
Attack Name: SCADA Protection Violation.
Attack Information: Advantech WebAccess SCADA ProjectName Parameter Buffer Overflow