CVE-2020-14499: Advantech iView UserServlet getAllUsersAccountInfo Improper Access Control Information Disclosure Vulnerability
Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UserServlet class. The issue results from the lack of proper access control. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14499?
CVE-2020-14499 is a vulnerability in Advantech iView that allows remote attackers to disclose sensitive information.
Is authentication required to exploit CVE-2020-14499?
No, authentication is not required to exploit this vulnerability.
What is the affected software of CVE-2020-14499?
The affected software is Advantech iView version up to and including 5.6.
What is the severity of CVE-2020-14499?
CVE-2020-14499 has a severity rating of 7.5 (high).
How can I fix CVE-2020-14499?
There is currently no known fix for this vulnerability. It is recommended to follow the suggestions provided by the vendor or CERT/CSIRT.