CVE-2020-14501: Advantech iView UserServlet performDeleteUser Missing Authentication for Critical Function Information Disclosure Vulnerability
Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulnerability may allow an attacker to obtain the information of the user table, including the administrator credentials in plain text. An attacker may also delete the administrator account.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UserServlet class. The issue results from the lack of authentication prior to allowing alterations to the system configuration. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14501?
CVE-2020-14501 is a vulnerability in Advantech iView that allows remote attackers to disclose sensitive information without authentication.
How severe is CVE-2020-14501?
CVE-2020-14501 has a severity rating of 9.8, which is considered critical.
How can CVE-2020-14501 be exploited?
CVE-2020-14501 can be exploited by remote attackers without authentication to disclose sensitive information.
What is the affected software for CVE-2020-14501?
The affected software for CVE-2020-14501 is Advantech iView version up to 5.6.
Are there any references available for CVE-2020-14501?
Yes, you can find references for CVE-2020-14501 at the following URLs: 1. https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01 2. https://www.zerodayinitiative.com/advisories/ZDI-20-859/ 3. https://us-cert.cisa.gov/ics/advisories/icsa-20-196-33