RULE(RULE ID:713467)

Rule General Information
Release Date: 2019-09-24
Rule Name: Advantech WebAccess SCADA BwPAlarm IOCTL 70603 Stack-based Buffer Overflow Vulnerability (CVE-2019-3975)
Severity:
CVE ID:
Rule Protection Details
Description: Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbitrary code via a crafted IOCTL 70603 RPC message.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Others
Reference: https://www.tenable.com/security/research/tra-2019-41
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.advantech.com