Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-2404 | The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call. |
Solution
Advantech released a new WebAccess Installation Package v7.2 on June 6, 2014, that removes some vulnerable ActiveX components and resolves the vulnerabilities within others. The download link for v7.2 is available at: http://webaccess.advantech.com/
Workaround
No workaround given by the vendor.
Mon, 06 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Advantech WebAccess Authentication Bypass Issues | |
| Weaknesses | CWE-592 | |
| References |
| |
| Metrics |
cvssV2_0
|
cvssV2_0
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-10-06T17:48:24.247Z
Reserved: 2014-03-13T00:00:00
Link: CVE-2014-2367
No data.
Status : Deferred
Published: 2014-07-19T05:09:27.720
Modified: 2025-10-06T18:15:48.380
Link: CVE-2014-2367
No data.
OpenCVE Enrichment
No data.
EUVD