CVE-2021-33004
Last modified
CVE-2021-33004 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).. EPSS estimates a 0.95% chance of exploitation in the next 30 days.
Description
The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Advantech | Webaccess\/Hmi Designer | <= 2.1.9.95 |
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33004?
How severe is CVE-2021-33004?
How do I fix CVE-2021-33004?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-32998The FANUC R-30iA and R-30iB series controllers are vulnerabl…7.4
- CVE-2021-32999Improper handling of exceptional conditions in SuiteLink ser…7.5
- CVE-2021-33000Parsing a maliciously crafted project file may cause a heap-…7.8
- CVE-2021-33001xArrow SCADA versions 7.2 and prior is vulnerable to cross-s…6.1
- CVE-2021-33002Opening a maliciously crafted project file may cause an out-…7.8
- CVE-2021-33003Delta Electronics DIAEnergie Version 1.7.5 and prior may all…5.5
- CVE-2021-33005mySCADA myPRO versions prior to 8.20.0 allows an unauthentic…7.5
- CVE-2021-33007A heap-based buffer overflow in Delta Electronics TPEditor: …7.8
- CVE-2021-33008AVEVA System Platform versions 2017 through 2020 R2 P01 does…9.8
- CVE-2021-33009mySCADA myPRO versions prior to 8.20.0 allows an unauthentic…7.5
- CVE-2021-33010An exception is thrown from a function in AVEVA System Platf…7.5
- CVE-2021-33011All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Pl…4.3
Are you affected by CVE-2021-33004?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
