Threat Encyclopedia

Advantech.WA.HMI.Designer.PM3.NHTrendGraph.Memory.Corruption

description-logoDescription

This indicates an attack attempt to exploit a Memory Corruption Vulnerability in Advantech WebAccess HMI Designer.
The vulnerability is due to lack of validation while processing user-supplied NHTrendGraph object data. A remote attacker can exploit this vulnerability by enticing a target user into opening a crafted PM3 file. Successful exploitation could result in the execution of arbitrary code under the security context of the target user.

affected-products-logoAffected Products

Advantech WebAccess HMI Designer

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Advantech has not released an advisory or patch regarding this vulnerability.

CVE References

CVE-2021-33004

Other References

ICSA-21-173-01