CVE-2022-50592: Advantech iView < v5.7.04 Build 6425 getInventoryReportData Parameter SQL Injection RCE
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘getInventoryReportData’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50592?
CVE-2022-50592 is considered a critical vulnerability due to its potential to allow remote attackers to exploit authentication bypass and SQL injection.
How do I fix CVE-2022-50592?
To fix CVE-2022-50592, upgrading Advantech iView to version 5.7.04 or later is necessary.
What type of vulnerability is CVE-2022-50592?
CVE-2022-50592 involves an authentication bypass and a SQL injection vulnerability.
What affected software versions are associated with CVE-2022-50592?
CVE-2022-50592 affects Advantech iView versions prior to v5.7.04 build 6425.
Can CVE-2022-50592 be exploited remotely?
Yes, CVE-2022-50592 can be exploited remotely by attackers leveraging the vulnerability in the SNMP management tool.