#VU41470 Information disclosure in Advantech WebAccess - CVE-2014-2366

 

#VU41470 Information disclosure in Advantech WebAccess - CVE-2014-2366

Published: July 19, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41470
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2014-2366
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Advantech WebAccess
Software vendor:
Advantech Co., Ltd

Description

The vulnerability allows a remote #AU# to gain access to sensitive information.

upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.


Remediation

Install update from vendor's website.

External links