First published: Thu Feb 11 2021(Updated: )
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech iView | <5.7.03.6112 | |
Advantech iView | ||
Advantech iView versions prior to v5.7.03.6112 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22654 is an SQL Injection Information Disclosure vulnerability in Advantech iView, which allows remote attackers to disclose sensitive information without authentication.
The vulnerability allows remote attackers to exploit Advantech iView installations and disclose sensitive information.
No, authentication is not required to exploit this vulnerability.
The severity of CVE-2021-22654 vulnerability is high, with a severity value of 7.5.
To fix the vulnerability, affected installations should apply the latest security patches or updates provided by Advantech.