Advantech WebAccess CVE-2014-2367 Remote Authentication Bypass Vulnerability
BID:68716
Info
Advantech WebAccess CVE-2014-2367 Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 68716 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-2367 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2014 12:00AM |
| Updated: | Jul 22 2014 12:07AM |
| Credit: | Dave Weinstein, Tom Gallagher, John Leitch, and others through ZDI |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Advantech WebAccess CVE-2014-2367 Remote Authentication Bypass Vulnerability
Advantech WebAccess is prone to a remote authentication bypass vulnerability.
Attackers can exploit this issue to gain access to previously restricted pages. This may aid in further attacks.
Advantech WebAccess 7.1 and prior are vulnerable.
Advantech WebAccess is prone to a remote authentication bypass vulnerability.
Attackers can exploit this issue to gain access to previously restricted pages. This may aid in further attacks.
Advantech WebAccess 7.1 and prior are vulnerable.
Exploit / POC
Advantech WebAccess CVE-2014-2367 Remote Authentication Bypass Vulnerability
Reports indicate that the exploit is publicly available. Please see the references for more information.
Reports indicate that the exploit is publicly available. Please see the references for more information.
Solution / Fix
Advantech WebAccess CVE-2014-2367 Remote Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Advantech WebAccess CVE-2014-2367 Remote Authentication Bypass Vulnerability
References:
References: