CVE-2014-2368CWE-623
Advantech WebAccess Unsafe ActiveX Control Marked Safe For Scripting
High · published July 19, 2014
What it is
The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.
The record
Technical detail
- CVSS v2.0
- 7.5 · HIGH
- Vector
- AV:N/AC:L/Au:N/C:P/I:P/A:P
- CVSS v4.0
- Not supplied
- EPSS
- 0.01710 · 75.8th percentile
- Weakness
- CWE-623 · Unsafe ActiveX Control Marked Safe For Scripting
- Published
- 2014-07-19T01:00Z
EPSS history
Timeline