{
    "id": "CVE-2014-2364",
    "published": "2014-07-19 05:09:27",
    "last_modified": "2026-06-17 00:06:29",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
    "cwe": "CWE-121",
    "description": "Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.",
    "epss_score": "0.61384",
    "epss_percentile": "0.99140",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-27 18:17:13",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "advantech",
            "product": "advantech_webaccess"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "34757",
            "title": "Advantech Webaccess - dvs.ocx GetColor Buffer Overflow (Metasploit)",
            "date": "2014-09-24",
            "url": "https://www.exploit-db.com/exploits/34757"
        }
    ],
    "refs_list": [
        "http://packetstormsecurity.com/files/128384/Advantech-WebAccess-dvs.ocx-GetColor-Buffer-Overflow.html",
        "http://webaccess.advantech.com/",
        "http://www.securityfocus.com/bid/68714",
        "https://www.cisa.gov/news-events/ics-advisories/icsa-14-198-02",
        "http://ics-cert.us-cert.gov/advisories/ICSA-14-198-02",
        "http://packetstormsecurity.com/files/128384/Advantech-WebAccess-dvs.ocx-GetColor-Buffer-Overflow.html",
        "http://www.securityfocus.com/bid/68714"
    ]
}