upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.

Project Subscriptions

Vendors Products
Advantech Subscribe
Advantech Webaccess Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2014-2403 upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.
Fixes

Solution

Advantech released a new WebAccess Installation Package v7.2 on June 6, 2014, that removes some vulnerable ActiveX components and resolves the vulnerabilities within others. The download link for v7.2 is available at: http://webaccess.advantech.com/


Workaround

No workaround given by the vendor.

History

Mon, 06 Oct 2025 18:00:00 +0000

Type Values Removed Values Added
Title Advantech WebAccess Cleartext Storage of Sensitive Information in Memory
Weaknesses CWE-316
References
Metrics cvssV2_0

{'score': 4.0, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N'}

cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-10-06T17:50:01.014Z

Reserved: 2014-03-13T00:00:00

Link: CVE-2014-2366

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-07-19T05:09:27.673

Modified: 2025-10-06T18:15:48.223

Link: CVE-2014-2366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses