Lucene search

K
zdiJohn LeitchZDI-14-249
HistoryJul 18, 2014 - 12:00 a.m.

Advantech WebAccess Remote Authentication Bypass Vulnerability

2014-07-1800:00:00
John Leitch
www.zerodayinitiative.com
14

EPSS

0.049

Percentile

92.9%

This vulnerability allows remote attackers to bypass authentication requirements on vulnerable installations of Advantech WebAccess. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ChkCookieNoRedir function. By providing arbitrary values to certain fields, an attacker can receive a session authentication cookie despite receiving an error message.

EPSS

0.049

Percentile

92.9%

Related for ZDI-14-249