ZDI-CAN-10633: Advantech iView DeviceTreeTable checkForChassisUpdates SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of calls to the checkForChassisUpdates method of the DeviceTreeTable class. When parsing the segment HTTP parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-10633?
ZDI-CAN-10633 has been classified with a high severity level due to its potential for remote code execution.
How do I fix ZDI-CAN-10633?
To mitigate ZDI-CAN-10633, users should update to the latest version of Advantech iView provided by the vendor.
What products are affected by ZDI-CAN-10633?
The vulnerability ZDI-CAN-10633 affects Advantech iView installations.
Can ZDI-CAN-10633 be exploited without authentication?
Yes, the vulnerability ZDI-CAN-10633 can be exploited without any authentication requirements.
What kind of attack does ZDI-CAN-10633 enable?
ZDI-CAN-10633 enables remote attackers to execute arbitrary code on affected systems.