CVE-2014-2364: Advantech Webaccess
High severity, CVSS 7.5. EPSS: 61.4% chance of exploitation in the next 30 days.
Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.
Affected products
- Advantech Advantech Webaccess: up to and including 7.1; version 5.0 only; version 6.0 only; version 7.0 only
Published 2014-07-19. Last modified 2026-06-17.