CVE-2021-33004

HIGH

WebAccess HMI Designer <2.1.9.95 - Memory Corruption

Title source: llm
STIX 2.1

Description

The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01

Scores

CVSS v3 7.8
EPSS 0.0036
EPSS Percentile 58.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119 CWE-787
Status published
Products (1)
advantech/webaccess\/hmi_designer < 2.1.9.95
Published Jun 24, 2021
Tracked Since Feb 18, 2026