CVE-2022-50595: Advantech iView < v5.7.04 Build 6425 ztp_search_value Parameter SQL Injection RCE
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztpsearchvalue’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50595?
CVE-2022-50595 has a high severity rating due to its potential for remote code execution resulting from SQL injection vulnerabilities.
How do I fix CVE-2022-50595?
To fix CVE-2022-50595, upgrade Advantech iView to version 5.7.04 build 6426 or later.
What kind of attacks can CVE-2022-50595 facilitate?
CVE-2022-50595 can allow remote attackers to bypass authentication and exploit SQL injection vulnerabilities.
Which versions of Advantech iView are affected by CVE-2022-50595?
CVE-2022-50595 affects Advantech iView versions prior to v5.7.04 build 6425.
Is authentication bypass a concern in CVE-2022-50595?
Yes, CVE-2022-50595 allows attackers to bypass authentication checks within the SNMP management tool.