Advantech.WebAccess.SCADA.bwocxrun.OCX.Command.Execution

description-logoDescription

This indicates an attack attempt against a Command Execution vulnerability in the Advantech WebAccess SCADA.
The vulnerability, which is located in the "bwocxrun.ocx" ActiveX control, can be exploited through a vulnerable function. An attacker can exploit this by tricking an unsuspecting user into visiting a malicious webpage and execute Operating System Commands within the context of the logged in users.

affected-products-logoAffected Products

Advantech WebAccess prior to 7.2

Impact logoImpact

System Compromise: Remote attackers can execute Operating System Commands within the context of the target users

recomended-action-logoRecommended Actions

Apply the latest update from the vendor.
http://webaccess.advantech.com/downloads.php?item=software

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)