CVE-2012-0239

Advantech Webaccess < 6.0 - Authentication Bypass

Title source: rule

Description

uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request.

Scores

EPSS 0.0018
EPSS Percentile 38.7%

Classification

CWE
CWE-287
Status draft

Affected Products (2)

advantech/advantech_webaccess < 6.0
advantech/advantech_webaccess

Timeline

Published Feb 21, 2012
Tracked Since Feb 18, 2026