First published: Tue Jun 28 2022(Updated: )
The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech iView | <5.7.04.6469 | |
Advantech iView_7_04_6469 | <5 | 5 |
Advantech recommends updating firmware to Version 5_7_4_6469 to address these vulnerabilities.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2136 is a vulnerability that allows an unauthorized attacker to perform multiple SQL injections in Advantech iView.
CVE-2022-2136 has a severity rating of 6.5 (High).
CVE-2022-2136 affects Advantech iView by enabling multiple SQL injections that can be exploited by an attacker with low privileges.
Advantech iView version 5.7.04.6469 is affected by CVE-2022-2136.
To mitigate the risk of CVE-2022-2136, it is recommended to update to a version of Advantech iView that is not affected by the vulnerability.