CVE-2014-2365: Advantech WebAccess Improper Access Control
Published Jul 19, 2014
·Updated
Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors.
Affected Software
4 affected components
Advantech Advantech WebAccess<=7.1
Advantech Advantech WebAccess=5.0
Advantech Advantech WebAccess=6.0
Advantech Advantech WebAccess=7.0
Remediation
Information
Advantech released a new WebAccess Installation Package v7.2 on June
6, 2014, that removes some vulnerable ActiveX components and resolves
the vulnerabilities within others. The download link for v7.2 is
available at:
http://webaccess.advantech.com/
Event History
Jul 19, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:09 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2365?
CVE-2014-2365 has been classified with a moderate severity as it allows authenticated users to create or delete arbitrary files.
2
How do I fix CVE-2014-2365?
To fix CVE-2014-2365, upgrade Advantech WebAccess to version 7.2 or later.
3
Which versions of Advantech WebAccess are affected by CVE-2014-2365?
CVE-2014-2365 affects Advantech WebAccess versions 5.0 to 7.1.
4
Can remote users exploit CVE-2014-2365?
No, CVE-2014-2365 requires authenticated users to exploit the vulnerability.
5
What types of attacks are possible with CVE-2014-2365?
CVE-2014-2365 can be exploited to create or delete arbitrary files, potentially leading to unauthorized access or disruption.