CVE-2017-14016
CVE-2017-14016
Vexday Risk Score
43Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 16.0%KEV nãoPoC públicaNuclei —Metasploit simPatch —
Lifecycle
02 Nov 2017Metasploit module available
06 Nov 2017Published on NVD
14 Dec 2017Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.
Affected products
n/a · Advantech WebAccesspublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/43340/unverifiedexploitdbwww.exploit-db.com/exploits/43340unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →