CVE-2014-0771: Advantech WebAccess File and Directory Information Exposure
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter and returns its contents to the caller in JavaScript. The URLs are accessed in the security context of the current browser session. The control does not perform any URL validation and allows “file://” URLs that access the local disk.
The method can be used to open a URL (including file URLs) and read file URLs through JavaScript. This method could also be used to reach any arbitrary URL to which the browser has access.
Other sources
The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Advantech WebAccessto a version that resolves this vulnerability.Fixed in 7.2
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0771?
CVE-2014-0771 has a medium severity rating due to its potential for information disclosure.
How do I fix CVE-2014-0771?
To fix CVE-2014-0771, upgrade Advantech WebAccess to version 7.2 or later.
Who is affected by CVE-2014-0771?
CVE-2014-0771 affects Advantech WebAccess versions 5.0 through 7.1.
What is the impact of CVE-2014-0771?
The impact of CVE-2014-0771 allows remote attackers to read arbitrary files on the system.
Is there a workaround for CVE-2014-0771?
Currently, there is no official workaround for CVE-2014-0771 other than upgrading the software.