CRITICAL🇵🇱 Wersja polska

CVE-2022-50593

CVSS 9.3v4.0pub. 2025-11-06upd. 2025-12-08

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

🤖 AI Analysis
How it works

An attacker can remotely, without needing an account, bypass authentication mechanisms (CWE-306) and directly reach the 'NetworkServlet' endpoint. Subsequently, through the vulnerable 'search_term' parameter, it is possible to conduct a SQL injection attack (CWE-89) against the application database. Successful exploitation of this vulnerability allows for remote code execution (RCE) in the context of the administrator account.

Impact

An attacker can gain full control over the compromised system with administrator privileges, including data reading and modification, as well as remote execution of arbitrary code.

Mitigation & patch

Advantech iView should be updated to version v5.7.04 build 6425 or later. Patches are available from the manufacturer at: https://www.advantech.tw/support/details/firmware?id=1-HIPU-183

Who is affected

Advantech iView in versions prior to v5.7.04 build 6425

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Advantech Iview

    APP
    Advantech
    < 5.7.04.6425
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCESQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2022-50595CRITICAL9.3PL ✓same product

Advantech iView — Auth Bypass + SQL Injection prowadzący do RCE

CVE-2022-50592CRITICAL9.3PL ✓same product

Advantech iView – Auth Bypass i SQL Injection prowadzące do RCE

CVE-2022-2143CRITICAL9.8PL ✓same product

Command Injection w Advantech iView umożliwiające zdalne RCE

CVE-2021-32930CRITICAL9.8PL ✓same product

Brak uwierzytelniania w Advantech iView umożliwia RCE

CVE-2021-22652CRITICAL9.8PL ✓same product

Brak uwierzytelnienia w konfiguracji Advantech iView — RCE