Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2xr-8jgc-jrmr

Опубликовано: 06 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 7.5

Описание

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.

EPSS

Процентиль: 37%
0.00162
Низкий

8.8 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.

CVSS3: 8.2
fstec
около 4 лет назад

Уязвимость инструмента управления SNMP системы централизованного управления сетевыми устройствами и портами Advantech iView, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 37%
0.00162
Низкий

8.8 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-89