{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T14:07:29.799","vulnerabilities":[{"cve":{"id":"CVE-2014-0767","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2014-04-12T04:37:31.567","lastModified":"2026-06-17T00:03:36.300","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An attacker may exploit this vulnerability by passing an overly long \nvalue from the AccessCode argument to the control. This will overflow \nthe static stack buffer. The attacker may then execute code on the \ntarget device remotely."},{"lang":"es","value":"Desbordamiento de buffer basado en pila en Advantech WebAccess anterior a 7.2 permite a atacantes remotos ejecutar código arbitrario a través de un argumento AccessCode largo."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Advantech","product":"WebAccess","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.1","versionType":"custom","status":"affected"},{"version":"7.2","status":"unaffected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]},{"source":"nvd@nist.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-119"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:advantech:advantech_webaccess:*:*:*:*:*:*:*:*","versionEndIncluding":"7.1","matchCriteriaId":"3D097D1E-9A02-40B0-93BD-163A11638118"},{"vulnerable":true,"criteria":"cpe:2.3:a:advantech:advantech_webaccess:5.0:*:*:*:*:*:*:*","matchCriteriaId":"090C819C-5964-4158-80E6-2D4751A5E8BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:advantech:advantech_webaccess:6.0:*:*:*:*:*:*:*","matchCriteriaId":"7CF61F9C-360A-4B70-951D-8EE9CF6E55FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:advantech:advantech_webaccess:7.0:*:*:*:*:*:*:*","matchCriteriaId":"1082E1D5-AF49-431F-9172-98C2D2887C96"}]}]}],"references":[{"url":"http://webaccess.advantech.com/","source":"ics-cert@hq.dhs.gov"},{"url":"http://www.securityfocus.com/bid/66740","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-079-03","source":"ics-cert@hq.dhs.gov"},{"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-079-03","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]},{"url":"http://www.securityfocus.com/bid/66728","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}