Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3323

Опубликовано: 27 сент. 2022
Источник: nvd
CVSS3: 7.5
EPSS Средний

Описание

An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:advantech:iview:5.7.04.6469:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.2862
Средний

7.5 High

CVSS3

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 7.5
github
почти 4 года назад

An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password.

CVSS3: 7.5
fstec
около 4 лет назад

Уязвимость компонента setConfiguration системы централизованного управления сетевыми устройствами и портами Advantech iView, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 98%
0.2862
Средний

7.5 High

CVSS3

Дефекты

CWE-89
CWE-89