This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DeviceTreeTable class. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-10717 is high due to the potential for remote attackers to disclose sensitive information.
To fix ZDI-CAN-10717, apply the latest software updates or patches provided by Advantech for iView.
ZDI-CAN-10717 is caused by insufficient access controls within the DeviceTreeTable class.
No, authentication is not required to exploit the ZDI-CAN-10717 vulnerability.
The potential impacts of ZDI-CAN-10717 include unauthorized disclosure of sensitive information from affected installations of Advantech iView.