CVE-2022-50594

Advantech iView versions prior to v5.7.04 build 6425contain a vulnerability within the SNMP management toolthat allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the data parameter to the NetworkServlet endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
VulnCheckCNA
---
---
CISA-ADPADP
---
---