Advantech WebAccess Webeye ActiveX Control Stack Based Buffer Overflow Vulnerability

high Nessus Plugin ID 81788

Synopsis

The remote host has an ActiveX control with a buffer overflow vulnerability.

Description

The Advantec WebAccess application installed on the remote host includes a third party 'webeye.ocx' ActiveX control that is affected by a stack-based buffer overflow vulnerability when processing input to the 'ip_address' parameter. A remote attacker, using a specially crafted HTML file, can exploit this to execute arbitrary code or crash the application.

Solution

Upgrade WebAccess to version 8.0 or later.

See Also

http://www.nessus.org/u?b9fbd0a4

https://ics-cert.us-cert.gov/advisories/ICSA-14-324-01

https://support.microsoft.com/en-us/help/240797/how-to-stop-an-activex-control-from-running-in-internet-explorer

Plugin Details

Severity: High

ID: 81788

File Name: scada_advantech_webaccess_8_0.nbin

Version: 1.128

Type: remote

Family: SCADA

Published: 3/12/2015

Updated: 4/23/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2014-8388

Vulnerability Information

CPE: cpe:/a:advantech:webaccess

Required KB Items: www/scada_advantech_webaccess

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/20/2014

Vulnerability Publication Date: 11/19/2014

Exploitable With

Core Impact

Reference Information

CVE: CVE-2014-8388

BID: 71193