CVE-2018-8837

HIGH

Advantech WebAccess HMI Designer <2.1.7.32 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103972
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-18-114-03

Scores

CVSS v3 7.8
EPSS 0.0037
EPSS Percentile 59.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
advantech/webaccess_hmi_designer < 2.1.7.32
Published Apr 25, 2018
Tracked Since Feb 18, 2026