CVE-2014-2364 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 61.4% (pctl 99)
Patch early
A public exploit exists.
Description
Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 61.38% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-121 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-07-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| advantech | advantech webaccess |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Advantech Webaccess - dvs.ocx GetColor Buffer Overflow (Metasploit) | 2014-09-24 |
References
- http://packetstormsecurity.com/files/128384/Advantech-WebAccess-dvs.ocx-GetColor-Buffer-Overflow.html
- http://webaccess.advantech.com/
- http://www.securityfocus.com/bid/68714
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-198-02
- http://ics-cert.us-cert.gov/advisories/ICSA-14-198-02
- http://packetstormsecurity.com/files/128384/Advantech-WebAccess-dvs.ocx-GetColor-Buffer-Overflow.html
- http://www.securityfocus.com/bid/68714
→ the Explorer · watch your stack · NVD