Advantech Iview

Do you want an email whenever new security vulnerabilities are reported in Advantech Iview?

By the Year

In 2024 there have been 0 vulnerabilities in Advantech Iview . Last year Iview had 1 security vulnerability published. Right now, Iview is on track to have less security vulnerabilities in 2024 than it did last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 1 8.80
2022 8 7.43
2021 6 8.65
2020 1 7.50
2019 0 0.00
2018 0 0.00

It may take a day or so for new Iview vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Advantech Iview Security Vulnerabilities

An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752

CVE-2023-3983 8.8 - High - July 31, 2023

An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.

SQL Injection

An SQL injection vulnerability in Advantech iView 5.7.04.6469

CVE-2022-3323 7.5 - High - September 27, 2022

An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password.

SQL Injection

The affected product is vulnerable to a SQL injection with high attack complexity, which may

CVE-2022-2142 5.9 - Medium - July 22, 2022

The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attacker to disclose information.

SQL Injection

The affected product is vulnerable due to missing authentication, which may

CVE-2022-2138 7.5 - High - July 22, 2022

The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition.

Missing Authentication for Critical Function

The affected product is vulnerable to two SQL injections

CVE-2022-2137 4.9 - Medium - July 22, 2022

The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information

SQL Injection

The affected product is vulnerable to multiple SQL injections

CVE-2022-2136 6.5 - Medium - July 22, 2022

The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information.

SQL Injection

The affected product is vulnerable to multiple SQL injections, which may

CVE-2022-2135 7.5 - High - July 22, 2022

The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information.

SQL Injection

The affected product is vulnerable to two instances of command injection, which may

CVE-2022-2143 9.8 - Critical - July 22, 2022

The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.

The affected product is vulnerable to directory traversal, which may

CVE-2022-2139 9.8 - Critical - July 22, 2022

The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.

Directory traversal

The affected product is vulnerable to a SQL injection, which may

CVE-2021-32932 7.5 - High - June 11, 2021

The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182).

SQL Injection

The affected products configuration is vulnerable due to missing authentication, which may

CVE-2021-32930 9.8 - Critical - June 11, 2021

The affected products configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arbitrary code on the iView (versions prior to v5.7.03.6182).

Missing Authentication for Critical Function

Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may

CVE-2021-22652 9.8 - Critical - February 11, 2021

Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution.

Missing Authentication for Critical Function

Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may

CVE-2021-22654 7.5 - High - February 11, 2021

Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information.

SQL Injection

Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may

CVE-2021-22656 7.5 - High - February 11, 2021

Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files.

Directory traversal

Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may

CVE-2021-22658 9.8 - Critical - February 11, 2021

Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'.

SQL Injection

Advantech iView, versions 5.6 and prior, has an improper access control vulnerability

CVE-2020-14499 7.5 - High - July 15, 2020

Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Advantech Iview or by Advantech? Click the Watch button to subscribe.

 

Advantech
Vendor

 
subscribe