CVE-2014-2368CWE-623

Advantech WebAccess Unsafe ActiveX Control Marked Safe For Scripting

High · published July 19, 2014

CVSS v2.0
7.5
EPSS
2%
Percentile
75.8
In the wild
Unconfirmed
What it is

The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.

The record
Technical detail
CVSS v2.0
7.5 · HIGH
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS v4.0
Not supplied
EPSS
0.01710 · 75.8th percentile
Weakness
CWE-623 · Unsafe ActiveX Control Marked Safe For Scripting
Published
2014-07-19T01:00Z
EPSS history
Timeline
  • 19 JUL 01:00Z
    Advantech WebAccess Unsafe ActiveX Control Marked Safe For Scripting
    cvelistv5