CVE-2018-8835

HIGH

Advantech WebAccess HMI Designer <2.1.7.32 - Memory Corruption

Title source: llm

Description

Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.

Scores

CVSS v3 7.8
EPSS 0.0035
EPSS Percentile 57.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status published

Affected Products (1)

advantech/webaccess_hmi_designer < 2.1.7.32

Timeline

Published Apr 25, 2018
Tracked Since Feb 18, 2026