CVE-2014-2365
Advantech WebAccess Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors.
Vulnerabilidad no especificada en Advantech WebAccess anterior a 7.2 permite a usuarios remotos autenticados crear o eliminar ficheros arbitrarios a través de vectores desconocidos.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Advantech WebAccess. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the gmicons.asp functionality. By providing crafted requests, an attacker is able to delete or create arbitrary files as the WebAccess service. An attacker may leverage this to run arbitrary code in the context of the WebAccess service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-03-13 CVE Reserved
- 2014-07-18 CVE Published
- 2024-08-06 CVE Updated
- 2024-10-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
http://ics-cert.us-cert.gov/advisories/ICSA-14-198-02 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Advantech Search vendor "Advantech" | Advantech Webaccess Search vendor "Advantech" for product "Advantech Webaccess" | <= 7.1 Search vendor "Advantech" for product "Advantech Webaccess" and version " <= 7.1" | - |
Affected
| ||||||
Advantech Search vendor "Advantech" | Advantech Webaccess Search vendor "Advantech" for product "Advantech Webaccess" | 5.0 Search vendor "Advantech" for product "Advantech Webaccess" and version "5.0" | - |
Affected
| ||||||
Advantech Search vendor "Advantech" | Advantech Webaccess Search vendor "Advantech" for product "Advantech Webaccess" | 6.0 Search vendor "Advantech" for product "Advantech Webaccess" and version "6.0" | - |
Affected
| ||||||
Advantech Search vendor "Advantech" | Advantech Webaccess Search vendor "Advantech" for product "Advantech Webaccess" | 7.0 Search vendor "Advantech" for product "Advantech Webaccess" and version "7.0" | - |
Affected
|