First published: Wed Jul 15 2020(Updated: )
Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech iView | <=5.6 | |
Advantech iView | ||
Advantech iView Versions 5.6 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14507.
The title of the vulnerability is Advantech iView MenuServlet Directory Traversal Information Disclosure Vulnerability.
The severity of CVE-2020-14507 is critical with a CVSS score of 9.8.
Advantech iView versions up to and including 5.6 are affected by CVE-2020-14507.
Remote attackers can exploit this vulnerability without authentication by executing arbitrary code on affected installations of Advantech iView.