First published: Fri Jul 22 2022(Updated: )
The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech iView | <5.7.04.6469 | |
Advantech iView_7_04_6469 | <5 | 5 |
Advantech recommends updating firmware to Version 5_7_4_6469 to address these vulnerabilities.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2137 is a vulnerability that affects the Advantech iView product and allows an unauthorized attacker to disclose information through SQL injections.
CVE-2022-2137 has a severity rating of 4.9 which is considered medium.
CVE-2022-2137 affects Advantech iView versions up to and excluding 5.7.04.6469.
The SQL injection vulnerabilities in CVE-2022-2137 require high privileges for exploitation.
At the moment, there is no specific fix available for CVE-2022-2137. It is recommended to follow any mitigation steps provided by the vendor or CERT/CSIRT.