SQL Injection Vulnerability in Advantech iView Solutions
CVE-2022-3323
7.5HIGH
Summary
An SQL injection vulnerability has been identified in Advantech iView, specifically in the ConfigurationServlet endpoint which operates on TCP port 8080 by default. This issue allows unauthenticated remote attackers to exploit the setConfiguration action by crafting a malicious column_value parameter. This manipulation bypasses the intended SQL injection checks, enabling attackers to potentially access sensitive information, such as the iView admin password. Organizations using iView 5.7.04.6469 should prioritize remediation to safeguard against potential vulnerabilities.
Affected Version(s)
Advantech iView Advantech iView 5.7.04.6469
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved