CRITICAL🇵🇱 Wersja polska

CVE-2022-50592

CVSS 9.3v4.0pub. 2025-11-06upd. 2025-11-24

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘getInventoryReportData’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

🤖 AI Analysis
How it works

An attacker without any authentication sends a specially crafted request to the 'NetworkServlet' endpoint, manipulating the 'getInventoryReportData' parameter. The SNMP tool's authentication mechanism can be completely bypassed (CWE-306), allowing access to code vulnerable to SQL injection. By injecting malicious SQL (CWE-89), the attacker can take control of the database and ultimately achieve remote code execution on the server.

Impact

Successful exploitation allows an attacker to remotely execute arbitrary code with administrator privileges, which can lead to complete system takeover, data exfiltration, and lateral movement within the network.

Mitigation & patch

Advantech iView should be updated to version v5.7.04 build 6425 or newer. The patch is available from the vendor at the address indicated in the references (Advantech Support). Until the update is applied, it is recommended to restrict network access to the SNMP management interface solely to trusted hosts using a firewall or network segmentation.

Who is affected

Advantech iView in all versions prior to v5.7.04 build 6425

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Advantech Iview

    APP
    Advantech
    < 5.7.04.6425
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCESQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2022-50595CRITICAL9.3PL ✓same product

Advantech iView — Auth Bypass + SQL Injection prowadzący do RCE

CVE-2022-50593CRITICAL9.3PL ✓same product

Advantech iView – Auth Bypass + SQL Injection prowadzące do RCE

CVE-2022-2143CRITICAL9.8PL ✓same product

Command Injection w Advantech iView umożliwiające zdalne RCE

CVE-2021-32930CRITICAL9.8PL ✓same product

Brak uwierzytelniania w Advantech iView umożliwia RCE

CVE-2021-22652CRITICAL9.8PL ✓same product

Brak uwierzytelnienia w konfiguracji Advantech iView — RCE