7.8

CVE-2018-8835

Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdvantechWebaccess Hmi Designer Version <= 2.1.7.32
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.08% 0.792
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-415 Double Free

The product calls free() twice on the same memory address.

http://www.securityfocus.com/bid/103972
Third Party Advisory
VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-114-03
Third Party Advisory
US Government Resource