Advantech WebAccess Command Injection
Summary
| CVE | CVE-2014-0773 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-04-12 04:37:31 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “CreateProcess.” This method contains validation to ensure an attacker cannot run arbitrary command lines. After validation, the values supplied in the HTML are passed to the Windows CreateProcessA API. The validation can be bypassed allowing for running arbitrary command lines. The command line can specify running remote files (example: UNC command line). A function exists at offset 100019B0 of bwocxrun.ocx. Inside this function, there are 3 calls to strstr to check the contents of the user specified command line. If “\setup.exe,” “\bwvbprt.exe,” or “\bwvbprtl.exe” are contained in the command line (strstr returns nonzero value), the command line passes validation and is then passed to CreateProcessA. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: CWE-77 | NVD-CWE-Other | CWE-77 CWE-77
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | [email protected] | Secondary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | CNA | CVSS | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Advantech | Advantech Webaccess | 5.0 | All | All | All |
| Application | Advantech | Advantech Webaccess | 6.0 | All | All | All |
| Application | Advantech | Advantech Webaccess | 7.0 | All | All | All |
| Application | Advantech | Advantech Webaccess | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advantech WebAccess Vulnerabilities | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | US Government Resource |
| webaccess.advantech.com | [email protected] | webaccess.advantech.com | |
| www.securityfocus.com/bid/66740 | [email protected] | www.securityfocus.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-14-079-03 | [email protected] | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Andrea Micalizzi, aka rgod, Tom Gallagher, and an independent anonymous researcher working with HP’s Zero Day Initiative (ZDI) (en)
Additional Advisory Data
Solutions
CNA: Advantech has created a new version (Version 7.2) that mitigates each of the vulnerabilities described above. Users may download this version from the following location at their web site: http://webaccess.advantech.com/downloads.php?item=software For additional information about WebAccess, please visit the following Advantech web site: http://webaccess.advantech.com/
There are currently no legacy QID mappings associated with this CVE.