9.8
CVSSv3

CVE-2021-22652

Published: 11/02/2021 Updated: 26/03/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized malicious user to change the configuration and obtain code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

advantech iview

Exploits

This Metasploit module exploits an unauthenticated configuration change combined with an unauthenticated file write primitive, leading to an arbitrary file write that allows for remote code execution as the user running iView, which is typically NT AUTHORITY\SYSTEM This issue was demonstrated in the vulnerable version 57025992 and fixed in vers ...