SQL Injection Vulnerability in Advantech iView Solutions
CVE-2022-3323
7.5HIGH
What is CVE-2022-3323?
An SQL injection vulnerability has been identified in Advantech iView, specifically in the ConfigurationServlet endpoint which operates on TCP port 8080 by default. This issue allows unauthenticated remote attackers to exploit the setConfiguration action by crafting a malicious column_value parameter. This manipulation bypasses the intended SQL injection checks, enabling attackers to potentially access sensitive information, such as the iView admin password. Organizations using iView 5.7.04.6469 should prioritize remediation to safeguard against potential vulnerabilities.
Affected Version(s)
Advantech iView Advantech iView 5.7.04.6469