Arbitrary Code Execution via Heap-Based Buffer Overflow in WebAccess HMI Designer

Arbitrary Code Execution via Heap-Based Buffer Overflow in WebAccess HMI Designer

CVE-2021-33000 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).

Learn more about our Web App Pen Testing.