An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the program to use an invalid memory address, resulting in a program crash.
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/102424 | vdb entry third party advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-18-004-02 | us government resource third party advisory broken link |