CVE-2019-10961
CVE-2019-10961
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 4.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
02 Aug 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution.
Affected products
n/a · Advantech WebAccess HMI DesignerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →