Vulnerability Details CVE-2022-50591
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.4%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-50591
-
cpe:2.3:a:advantech:iview:5.6
-
cpe:2.3:a:advantech:iview:5.7
-
cpe:2.3:a:advantech:iview:5.7.02
-
cpe:2.3:a:advantech:iview:5.7.03.6112
-
cpe:2.3:a:advantech:iview:5.7.03.6182