CVE-2022-2137: Advantech iView
Published Jul 22, 2022
·Updated
The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information
Affected Software
2 affected componentsFixes available
Advantech iView_7_04_6469<5
5
Advantech iView<5.7.04.6469
Remediation
Information
Advantech recommends updating firmware to Version 5_7_4_6469 to address these vulnerabilities.
Event History
Jul 22, 2022
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-2137?
CVE-2022-2137 is a vulnerability that affects the Advantech iView product and allows an unauthorized attacker to disclose information through SQL injections.
2
How severe is CVE-2022-2137?
CVE-2022-2137 has a severity rating of 4.9 which is considered medium.
3
What software is affected by CVE-2022-2137?
CVE-2022-2137 affects Advantech iView versions up to and excluding 5.7.04.6469.
4
How can the SQL injection vulnerabilities in CVE-2022-2137 be exploited?
The SQL injection vulnerabilities in CVE-2022-2137 require high privileges for exploitation.
5
Is there a fix for CVE-2022-2137?
At the moment, there is no specific fix available for CVE-2022-2137. It is recommended to follow any mitigation steps provided by the vendor or CERT/CSIRT.