9.8
CVSSv3

CVE-2020-14497

Published: 15/07/2020 Updated: 21/07/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

advantech iview

References

CWE-89https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01https://www.zerodayinitiative.com/advisories/ZDI-20-858/https://www.zerodayinitiative.com/advisories/ZDI-20-836/https://www.zerodayinitiative.com/advisories/ZDI-20-848/https://www.zerodayinitiative.com/advisories/ZDI-20-856/https://www.zerodayinitiative.com/advisories/ZDI-20-868/https://www.zerodayinitiative.com/advisories/ZDI-20-846/https://www.zerodayinitiative.com/advisories/ZDI-20-838/https://www.zerodayinitiative.com/advisories/ZDI-20-828/https://www.zerodayinitiative.com/advisories/ZDI-20-850/https://www.zerodayinitiative.com/advisories/ZDI-20-862/https://www.zerodayinitiative.com/advisories/ZDI-20-860/https://www.zerodayinitiative.com/advisories/ZDI-20-854/https://www.zerodayinitiative.com/advisories/ZDI-20-832/https://www.zerodayinitiative.com/advisories/ZDI-20-844/https://www.zerodayinitiative.com/advisories/ZDI-20-866/https://www.zerodayinitiative.com/advisories/ZDI-20-852/https://www.zerodayinitiative.com/advisories/ZDI-20-830/https://www.zerodayinitiative.com/advisories/ZDI-20-864/https://www.zerodayinitiative.com/advisories/ZDI-20-842/https://www.zerodayinitiative.com/advisories/ZDI-20-847/https://www.zerodayinitiative.com/advisories/ZDI-20-869/https://www.zerodayinitiative.com/advisories/ZDI-20-837/https://www.zerodayinitiative.com/advisories/ZDI-20-845/https://www.zerodayinitiative.com/advisories/ZDI-20-857/https://www.zerodayinitiative.com/advisories/ZDI-20-835/https://www.zerodayinitiative.com/advisories/ZDI-20-827/https://www.zerodayinitiative.com/advisories/ZDI-20-849/https://www.zerodayinitiative.com/advisories/ZDI-20-839/https://www.zerodayinitiative.com/advisories/ZDI-20-861/https://www.zerodayinitiative.com/advisories/ZDI-20-851/https://www.zerodayinitiative.com/advisories/ZDI-20-865/https://www.zerodayinitiative.com/advisories/ZDI-20-843/https://www.zerodayinitiative.com/advisories/ZDI-20-855/https://www.zerodayinitiative.com/advisories/ZDI-20-833/https://www.zerodayinitiative.com/advisories/ZDI-20-863/https://www.zerodayinitiative.com/advisories/ZDI-20-853/https://nvd.nist.gov