QID 590986

QID 590986: Advantech iView Multiple Vulnerabilities (ICSA-22-179-03)

Multiple vulerbilities: SQL Injection, Missing Authentication for Critical Function, Relative Path Traversal, Command Injection were discovered in Advantech IView

AFFECTED PRODUCTS
The following versions of Advantech iView management software are affected:
Advantech iView: All versions prior to 5_7_04_6469

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of these vulnerabilities could allow an attacker to read or modify sensitive data, disclose information, or execute arbitrary code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-179-03 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-179-03 URL Logo www.us-cert.gov/ics/advisories/ICSA-22-179-03