HIGH
WebAccess Versions 8.3.2 and prior
Published Oct 29, 2018
7.8
HIGHCVSS 3.0
EPSS 5.22%
Description
WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing a buffer overflow condition that allows for arbitrary remote code execution.
Affected products
- Vendor n/a Product WebAccess Versions 8.3.2 and prior. Defaultn/a
- Version WebAccess Versions 8.3.2 and prior.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | WebAccess Versions 8.3.2 and prior. | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (3)
- http://www.securityfocus.com/bid/105736 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041957 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-298-02 x_refsource_MISCThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/105736 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1041957 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-298-02 | x_refsource_MISCThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Oct 29, 2018
Updated Aug 5, 2024
Reserved Oct 2, 2018
Link CVE-2018-17910
CISA Vulnrichment
Updated n/a