← Back to browse · API

CVE-2014-2364

Severity
HIGH
CVSS
7.5
EPSS
0.61384
Risk score
51.48
CISA KEV
No
PoC
No
Published
2014-07-19
Modified
2025-10-06
First seen
2026-08-07
Aliases
EUVD-2014-2401, GHSA-WC68-M5J4-WXR7
Products
Advantech:WebAccess 0 ≤7.1
Sources
euvd EUVD-2014-2401

Description

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.

References