First published: Thu Feb 11 2021(Updated: )
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech iView | <5.7.03.6112 | |
Advantech iView | ||
Advantech iView versions prior to v5.7.03.6112 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-22658.
The severity of CVE-2021-22658 is critical with a severity value of 9.8.
CVE-2021-22658 affects Advantech iView versions up to and excluding 5.7.03.6112.
An attacker can exploit CVE-2021-22658 by escalating privileges on affected installations of Advantech iView through a SQL injection vulnerability in the UserServlet class.
Yes, there are advisories and references available for CVE-2021-22658. You can find them at the following links: - [US-CERT Advisory](https://us-cert.cisa.gov/ics/advisories/icsa-21-040-02) - [Zero Day Initiative Advisory](https://www.zerodayinitiative.com/advisories/ZDI-21-191/)