RULE(RULE ID:712911)

Rule General Information
Release Date: 2019-07-03
Rule Name: Advantech WebAccess SCADA viewdll1 Stack Buffer Overflow Vulnerability -2 (CVE-2019-3954)
Severity:
CVE ID:
Rule Protection Details
Description: Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 81024 RPC call.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: https://www.tenable.com/security/research/tra-2019-28
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.advantech.com/