This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UserServlet class. The issue results from the lack of proper access control. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-10701 is considered high due to its potential for remote information disclosure without authentication.
To fix ZDI-CAN-10701, update the Advantech iView software to the latest version that includes the patch for this vulnerability.
ZDI-CAN-10701 affects installations of Advantech iView that have not been updated to address this vulnerability.
Currently, there are no known workarounds for ZDI-CAN-10701 other than applying the recommended updates.
ZDI-CAN-10701 is a remote information disclosure vulnerability in the UserServlet class of Advantech iView.