SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Advantech WebAccess webvact.ocx GetColor Buffer Overflow

Category: SCADA-ATTACKS      

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2364


Relevant Information