Back

HIGH

Advantech WebAccess Unsafe ActiveX Control Marked Safe For Scripting

Published Jul 19, 2014

Description

The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.

Affected products

Remediation

Vendor solution

Advantech released a new WebAccess Installation Package v7.2 on June 6, 2014, that removes some vulnerable ActiveX components and resolves the vulnerabilities within others. The download link for v7.2 is available at:

http://webaccess.advantech.com/

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jul 19, 2014
Updated Oct 6, 2025
Reserved Mar 13, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a