First published: Sat Jul 19 2014(Updated: )
upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebOP | <=7.1 | |
Advantech WebOP | =5.0 | |
Advantech WebOP | =6.0 | |
Advantech WebOP | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2366 is rated as medium severity due to its potential to allow credential discovery.
To fix CVE-2014-2366, upgrade Advantech WebAccess to version 7.2 or later.
Users of Advantech WebAccess versions prior to 7.2, including versions 5.0, 6.0, and 7.0, are affected by CVE-2014-2366.
CVE-2014-2366 allows remote authenticated users to discover sensitive credentials through the HTML source code.
Currently, the recommended action for CVE-2014-2366 is to upgrade to a secure version, as there are no acknowledged workarounds.