Description
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘getInventoryReportData’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-306 Missing Authentication for Critical Function
Product status
Any version before 5.7.04 build 6425
Timeline
| 2022-03-01: | Exodus Intelligence publicly discloses technical details of vulnerability. |
| 2022-01-27: | Advantech releases patched version - 5.7.04 build 6425. |
Credits
Exodus Intelligence
References
www.advantech.tw/support/details/firmware?id=1-HIPU-183
blog.exodusintel.com/...ql-injection-information-disclosure/
www.vulncheck.com/...tinventoryreportdata-parameter-sqli-rce