CRITICAL🇵🇱 Wersja polska

CVE-2022-50595

CVSS 9.3v4.0pub. 2025-11-06upd. 2025-11-24

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_search_value’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

🤖 AI Analysis
How it works

An attacker remotely bypasses authentication mechanisms (CWE-306) in the SNMP management tool of the iView application, thus gaining access to the 'NetworkServlet' endpoint. Then, through the 'ztp_search_value' parameter, injects malicious SQL queries (CWE-89). Successful exploitation of the SQL injection vulnerability allows escalation of the attack to remote code execution (RCE) level with administrator privileges.

Impact

An attacker can gain full control of the Advantech iView system with administrator privileges, including reading, modifying or deleting data and executing arbitrary code on the server.

Mitigation & patch

Advantech iView must be updated immediately to version v5.7.04 build 6425 or later. Patches are available from the manufacturer at: https://www.advantech.tw/support/details/firmware?id=1-HIPU-183. Until the update is implemented, it is recommended to restrict network access to the iView management interface to trusted hosts only and to isolate the system using a firewall.

Who is affected

Advantech iView in all versions earlier than v5.7.04 build 6425.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Advantech Iview

    APP
    Advantech
    < 5.7.04.6425
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCESQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2022-50593CRITICAL9.3PL ✓same product

Advantech iView – Auth Bypass + SQL Injection prowadzące do RCE

CVE-2022-50592CRITICAL9.3PL ✓same product

Advantech iView – Auth Bypass i SQL Injection prowadzące do RCE

CVE-2022-2143CRITICAL9.8PL ✓same product

Command Injection w Advantech iView umożliwiające zdalne RCE

CVE-2021-32930CRITICAL9.8PL ✓same product

Brak uwierzytelniania w Advantech iView umożliwia RCE

CVE-2021-22652CRITICAL9.8PL ✓same product

Brak uwierzytelnienia w konfiguracji Advantech iView — RCE