CVE-2014-0772

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named 
OpenUrlToBufferTimeout. This method takes a URL as a parameter and 
returns its contents to the caller in JavaScript. The URLs are accessed 
in the security context of the current browser session. The control does
 not perform any URL validation and allows file:// URLs that access the 
local disk.


The method can be used to open a URL (including file URLs) and read 
the URLs through JavaScript. This method could also be used to reach any
 arbitrary URL to which the browser has access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
icscertCNA
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
advantechadvantech_webaccess
𝑥
≤ 7.1
advantechadvantech_webaccess
5.0
advantechadvantech_webaccess
6.0
advantechadvantech_webaccess
7.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
advantechwebaccess
𝑥
≤ 7.1
CNA