Advantech WebAccess CVE-2014-2365 Remote Code Execution Vulnerability
BID:68718
Info
Advantech WebAccess CVE-2014-2365 Remote Code Execution Vulnerability
| Bugtraq ID: | 68718 |
| Class: | Design Error |
| CVE: |
CVE-2014-2365 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2014 12:00AM |
| Updated: | Jul 22 2014 12:07AM |
| Credit: | Dave Weinstein, Tom Gallagher, John Leitch, and others through ZDI |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Advantech WebAccess CVE-2014-2365 Remote Code Execution Vulnerability
Advantech WebAccess is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will likely cause a denial-of-service condition.
Advantech WebAccess 7.1 and prior are vulnerable.
Advantech WebAccess is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will likely cause a denial-of-service condition.
Advantech WebAccess 7.1 and prior are vulnerable.
Exploit / POC
Advantech WebAccess CVE-2014-2365 Remote Code Execution Vulnerability
Reports indicate that exploit is publicly available. Please see the references for more information.
Reports indicate that exploit is publicly available. Please see the references for more information.
Solution / Fix
Advantech WebAccess CVE-2014-2365 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Advantech WebAccess CVE-2014-2365 Remote Code Execution Vulnerability
References:
References: