Security Advisory

CVE-2014-2364

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-07-19 01:00:00
Last updated 2025-10-06 17:52:36
Assigner icscert
CVSS score 7.5
State PUBLISHED

Description

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.