Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-3323

An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.7%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2022-3323
  • Advantech » Iview » Version: 5.7.04.6469
    cpe:2.3:a:advantech:iview:5.7.04.6469


Contact Us

Shodan ® - All rights reserved