Advantech WebAccess Buffer Overflow Vulnerability (CVE-2016-0860)
Advantech WebAccess Buffer Overflow Vulnerability (CVE-2016-0860)
Release date:
Updated on:
Affected Systems:
Advantech WebAccess <8.1
Description:
CVE (CAN) ID: CVE-2016-0860
WebAccess HMI/SCADA software provides remote control and management, allowing you to easily view and configure automation devices in the facility management system, power station and building automation system.
In versions earlier than Advantech WebAccess 8.1, The BwpAlarm subsystem has a buffer overflow vulnerability. Remote attackers can exploit this vulnerability to cause denial of service by constructing RPC requests.
<* Source: Ilya Karpov
*>
Suggestion:
Vendor patch:
Advantech
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.advantech.com/industrial-automation/webaccess
This article permanently updates the link address: