CVE-2021-33000
Last modified
CVE-2021-33000 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).. EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Advantech | Webaccess\/Hmi Designer | <= 2.1.9.95 |
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33000?
How severe is CVE-2021-33000?
How do I fix CVE-2021-33000?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-32994Softing OPC UA C++ SDK (Software Development Kit) versions f…7.5
- CVE-2021-32995Cscape (All Versions prior to 9.90 SP5) lacks proper validat…7.8
- CVE-2021-32996The FANUC R-30iA and R-30iB series controllers are vulnerabl…7.5
- CVE-2021-32997The affected Baker Hughes Bentley Nevada products (3500 Syst…7.5
- CVE-2021-32998The FANUC R-30iA and R-30iB series controllers are vulnerabl…7.4
- CVE-2021-32999Improper handling of exceptional conditions in SuiteLink ser…7.5
- CVE-2021-33001xArrow SCADA versions 7.2 and prior is vulnerable to cross-s…6.1
- CVE-2021-33002Opening a maliciously crafted project file may cause an out-…7.8
- CVE-2021-33003Delta Electronics DIAEnergie Version 1.7.5 and prior may all…5.5
- CVE-2021-33004The affected product is vulnerable to memory corruption cond…7.8
- CVE-2021-33005mySCADA myPRO versions prior to 8.20.0 allows an unauthentic…7.5
- CVE-2021-33007A heap-based buffer overflow in Delta Electronics TPEditor: …7.8
Are you affected by CVE-2021-33000?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
