# CVE-2014-2368

## Summary

- **CVE ID:** CVE-2014-2368
- **Severity:** UNKNOWN
- **CVSS Score:** 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
- **CWE:** CWE-623
- **Published:** Jul 19, 2014
- **Last Modified:** Mar 14, 2026

## Description

The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.

## Affected Products

- Advantech — WebAccess (0)
- Advantech — WebAccess (7.2)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-14-198-02)
- [CNA](http://webaccess.advantech.com/)
- [CVE](http://ics-cert.us-cert.gov/advisories/ICSA-14-198-02)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.51%
- **EPSS Percentile:** 66.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._