RULE(RULE ID:1105172)

Rule General Information
Release Date: 2019-07-30
Rule Name: Advantech WebAccess SCADA BwPAlarm IOCTL 70605 Stack-based Buffer Overflow Vulnerability -1 (CVE-2019-10991)
Severity:
CVE ID:
Rule Protection Details
Description: In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: https://www.us-cert.gov/ics/advisories/icsa-19-178-05
ZeroDayInitiative:ZDI-19-586
ZeroDayInitiative:ZDI-19-588
ZeroDayInitiative:ZDI-19-589
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.advantech.com/