Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_search_value’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.
An attacker remotely bypasses authentication mechanisms (CWE-306) in the SNMP management tool of the iView application, thus gaining access to the 'NetworkServlet' endpoint. Then, through the 'ztp_search_value' parameter, injects malicious SQL queries (CWE-89). Successful exploitation of the SQL injection vulnerability allows escalation of the attack to remote code execution (RCE) level with administrator privileges.
An attacker can gain full control of the Advantech iView system with administrator privileges, including reading, modifying or deleting data and executing arbitrary code on the server.
Advantech iView must be updated immediately to version v5.7.04 build 6425 or later. Patches are available from the manufacturer at: https://www.advantech.tw/support/details/firmware?id=1-HIPU-183. Until the update is implemented, it is recommended to restrict network access to the iView management interface to trusted hosts only and to isolate the system using a firewall.
Advantech iView in all versions earlier than v5.7.04 build 6425.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAdvantech Iview
APPAdvantech< 5.7.04.6425
Related vulnerabilities
Advantech iView – Auth Bypass + SQL Injection prowadzące do RCE
Advantech iView – Auth Bypass i SQL Injection prowadzące do RCE
Command Injection w Advantech iView umożliwiające zdalne RCE
Brak uwierzytelniania w Advantech iView umożliwia RCE
Brak uwierzytelnienia w konfiguracji Advantech iView — RCE