CVE-2020-16207
CVE-2020-16207
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS —EPSS 3.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
06 ago 2020Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by opening specially crafted project files that may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
Produtos afetados
n/a · Advantech WebAccess HMI DesignerQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://us-cert.cisa.gov/ics/advisories/icsa-20-219-02https://www.zerodayinitiative.com/advisories/ZDI-20-950/https://www.zerodayinitiative.com/advisories/ZDI-20-951/https://www.zerodayinitiative.com/advisories/ZDI-20-955/https://www.zerodayinitiative.com/advisories/ZDI-20-958/https://www.zerodayinitiative.com/advisories/ZDI-20-959/