CVE-2020-16213
Description
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Advantech WebAccess HMI Designer versions up to 2.1.9.31 fail to validate user-supplied data when parsing PM3 project files, leading to an out-of-bounds write that can enable remote code execution or application crash.
Vulnerability
CVE-2020-16213 is an out-of-bounds write vulnerability (CWE-787) in Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. The flaw occurs during the parsing of specially crafted Project Model 3 (PM3) project files. The software lacks proper validation of user-supplied data, which can result in writing data past the end of an allocated buffer [1], [2].
Exploitation
An attacker can exploit this vulnerability by convincing a user to open a malicious PM3 project file. Remote exploitation is possible if the target visits a malicious page or opens a malicious file via email. No authentication is required, and the attack complexity is low. The user must interact with the crafted file, making it a user-assisted attack [1], [2].
Impact
Successful exploitation allows an attacker to execute arbitrary code in the context of the current process (the HMI Designer application). This can lead to remote code execution, disclosure or modification of information, or cause the application to crash. The CVSS v3 base score is 7.8, with vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [1], [2].
Mitigation
Advantech has released an update to address the vulnerability. The fixed version is WebAccess HMI Designer 2.1.9.32, according to the CISA advisory. Users should update to this or a later version. There are no known workarounds. This CVE is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Advantech/WebAccess HMI Designerdescription
- Range: <=2.1.9.31
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- us-cert.cisa.gov/ics/advisories/icsa-20-219-02mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-20-956/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.