SQL Injection Vulnerability in Advantech iView SNMP Management Tool
CVE-2022-50592
9.3CRITICAL
What is CVE-2022-50592?
Advantech iView versions prior to v5.7.04 build 6425 are susceptible to an authentication bypass within the SNMP management tool. This vulnerability allows remote attackers to exploit the 'getInventoryReportData' parameter in the 'NetworkServlet' endpoint, potentially leading to SQL injection. Successful exploitation can result in remote code execution with administrator privileges, granting attackers significant control of the affected system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
iView 0 < 5.7.04 build 6425
