Advantech / BroadWin WebAccess Client 'bwocxrun.ocx ' Multiple Remote Vulnerabilities

This script is Copyright (C) 2011-2015 Tenable Network Security, Inc.

Synopsis :

The remote Windows host has an ActiveX control that is affected by
multiple remote vulnerabilites.

Description :

The Advantech / BroadWin WebAccess Client ActiveX (bwocxrun.ocx)
installed on the remote host is reportedly affected by multiple issues
including a format string vulnerability and multiple memory corruption

By tricking a victim into visiting a specially crafted web page, an
attacker could take advantage of one of these issues to execute
arbitrary code in the context of the application.

See also :

Solution :

Either remove the software or set the kill bit for the affected

Risk factor :

High / CVSS Base Score : 9.3
CVSS Temporal Score : 8.4
Public Exploit Available : true

Family: SCADA

Nessus Plugin ID: 56993 ()

Bugtraq ID: 49428