Advantech WebAccess CVE-2014-2368 Unsafe ActiveX Control Remote Security Weakness
BID:68715
Info
Advantech WebAccess CVE-2014-2368 Unsafe ActiveX Control Remote Security Weakness
| Bugtraq ID: | 68715 |
| Class: | Configuration Error |
| CVE: |
CVE-2014-2368 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2014 12:00AM |
| Updated: | Jul 22 2014 12:07AM |
| Credit: | Dave Weinstein, Tom Gallagher, John Leitch, and others through ZDI |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Advantech WebAccess CVE-2014-2368 Unsafe ActiveX Control Remote Security Weakness
Advantech WebAccess is prone to a remote security weakness.
Attackers can exploit this issue to access arbitrary local files within the context of the application. This may aid in further attacks.
Advantech WebAccess 7.1 and prior are vulnerable.
Advantech WebAccess is prone to a remote security weakness.
Attackers can exploit this issue to access arbitrary local files within the context of the application. This may aid in further attacks.
Advantech WebAccess 7.1 and prior are vulnerable.
Exploit / POC
Advantech WebAccess CVE-2014-2368 Unsafe ActiveX Control Remote Security Weakness
Reports indicate that the exploit is publicly available. Please see the references for more information.
Reports indicate that the exploit is publicly available. Please see the references for more information.
Solution / Fix
Advantech WebAccess CVE-2014-2368 Unsafe ActiveX Control Remote Security Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Advantech WebAccess CVE-2014-2368 Unsafe ActiveX Control Remote Security Weakness
References:
References: