Description
A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. An input parameter can be used directly in a command without proper sanitization, allowing arbitrary arguments to be injected. This can result in information disclosure, including sensitive database credentials.
Problem types
Product status
Any version before 5.7.05 build 7057
Credits
Alex Williams of Converge Technology Solutions reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-191-08
www.advantech.com/en/support/details/firmware-?id=1-HIPU-183