Advantech WebAccess HMI Designer, Versions 126.96.36.199 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a type confusion condition, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
Weakness: Access of Resource Using Incompatible Type ('Type Confusion')
The program allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
This section is open source, for any additional information that enhances or clarifies the official advisory above.
Exploits for CVE-2020-16229 are not publicly available.