Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-52335

Опубликовано: 22 нояб. 2024
Источник: nvd
CVSS3: 7.5
CVSS3: 7.5
EPSS Низкий

Описание

Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the ConfigurationServlet servlet, which listens on TCP port 8080 by default. When parsing the column_value element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-17863.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:advantech:iview:*:*:*:*:*:*:*:*
Версия до 5.7.04.6752 (исключая)

EPSS

Процентиль: 54%
0.00318
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.5
github
около 1 года назад

Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ConfigurationServlet servlet, which listens on TCP port 8080 by default. When parsing the column_value element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-17863.

EPSS

Процентиль: 54%
0.00318
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-89