First published: Wed Jul 15 2020(Updated: )
Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulnerability may allow an attacker to obtain the information of the user table, including the administrator credentials in plain text. An attacker may also delete the administrator account.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech iView | <=5.6 | |
Advantech iView | ||
Advantech iView Versions 5.6 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14501 is a vulnerability in Advantech iView that allows remote attackers to disclose sensitive information without authentication.
CVE-2020-14501 has a severity rating of 9.8, which is considered critical.
CVE-2020-14501 can be exploited by remote attackers without authentication to disclose sensitive information.
The affected software for CVE-2020-14501 is Advantech iView version up to 5.6.
Yes, you can find references for CVE-2020-14501 at the following URLs: 1. https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01 2. https://www.zerodayinitiative.com/advisories/ZDI-20-859/ 3. https://us-cert.cisa.gov/ics/advisories/icsa-20-196-33