peter bassill · operator
$ cve CVE-2017-12708 JSON

CVE-2017-12708

9.8
CRITICAL · CVSS 3.0 · EPSS 3.4% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An Improper Restriction Of Operations Within The Bounds Of A Memory Buffer issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities that allow invalid locations to be referenced for the memory buffer, which may allow an attacker to execute arbitrary code or cause the system to crash.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.39% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2017-08-30
Last modified2026-06-17

Affected (1)

VendorProduct
advantechwebaccess

References

→ the Explorer  ·  watch your stack  ·  NVD