CVE-2014-2366
Advantech WebAccess Password Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.
upAdminPg.asp en Advantech WebAccess anterior a 7.2 permite a usuarios remotos autenticados descubrir credenciales mediante la lectura del código fuente HTML.
This vulnerability allows remote attackers to disclose arbitrary credentials on vulnerable versions of Advantech WebAccess. Authentication is required to exploit this vulnerability.
The specific flaw exists within the upAdminPg.asp component. An authenticated user can provide an arbitrary existing account name to this page and receive the account password. An attacker can leverage this vulnerability to then authenticate as the WebAccess Administrator.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-03-13 CVE Reserved
- 2014-07-18 CVE Published
- 2024-08-06 CVE Updated
- 2024-10-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
http://ics-cert.us-cert.gov/advisories/ICSA-14-198-02 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Advantech Search vendor "Advantech" | Advantech Webaccess Search vendor "Advantech" for product "Advantech Webaccess" | <= 7.1 Search vendor "Advantech" for product "Advantech Webaccess" and version " <= 7.1" | - |
Affected
| ||||||
Advantech Search vendor "Advantech" | Advantech Webaccess Search vendor "Advantech" for product "Advantech Webaccess" | 5.0 Search vendor "Advantech" for product "Advantech Webaccess" and version "5.0" | - |
Affected
| ||||||
Advantech Search vendor "Advantech" | Advantech Webaccess Search vendor "Advantech" for product "Advantech Webaccess" | 6.0 Search vendor "Advantech" for product "Advantech Webaccess" and version "6.0" | - |
Affected
| ||||||
Advantech Search vendor "Advantech" | Advantech Webaccess Search vendor "Advantech" for product "Advantech Webaccess" | 7.0 Search vendor "Advantech" for product "Advantech Webaccess" and version "7.0" | - |
Affected
|