CVE-2022-50591

Advantech iView versions prior to v5.7.04 build 6425contain a vulnerability within the SNMP management toolthat allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ztp_config_id parameter to the NetworkServlet endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
VulnCheckCNA
---
---
CISA-ADPADP
---
---