9.8
CVSSv3

CVE-2022-2143

Published: 22/07/2022 Updated: 24/07/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The affected product is vulnerable to two instances of command injection, which may allow an malicious user to remotely execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

advantech iview

ICS Advisories

Exploits

Advantech iView software versions prior to 57046469 are vulnerable to an unauthenticated command injection vulnerability via the NetworkServlet endpoint The database backup functionality passes a user-controlled parameter, backup_file to the mysqldump command The sanitization functionality only tests for SQL injection attempts and directory tr ...