PT-2020-14838 · Advantech · Iview

Published

2020-08-25

·

Updated

2020-08-31

·

CVE-2020-16245

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech iView versions 5.7 and prior
Description The affected product is vulnerable to path traversal vulnerabilities, which could allow an attacker to create or download arbitrary files, limit system availability, and remotely execute code. The vulnerability affects various components, including the DeviceTreeTable, NetworkServlet, TaskMgrTable, and PSTable, allowing for directory traversal, remote code execution, and information disclosure.
Recommendations For versions 5.7 and prior, update to a version later than 5.7 to resolve the issue. As a temporary workaround, consider restricting access to the affected components, such as the DeviceTreeTable, NetworkServlet, TaskMgrTable, and PSTable, to minimize the risk of exploitation. Avoid using the affected API endpoints, such as DeviceTreeTable exportTaskMgrReport, NetworkServlet findCfgDeviceListExport, DeviceTreeTable exportInventoryTable, NetworkServlet findSummaryCfgDeviceListExport, TaskMgrTable exportTaskMgrReportDetails, NetworkServlet findUpdateDeviceListExport, NetworkServlet backupDatabase, NetworkServlet findSummaryUpdateDeviceListExport, and PSTable exportPSInventoryTable, until the issue is resolved.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-16245
ZDI-20-1084
ZDI-20-1085
ZDI-20-1086
ZDI-20-1087
ZDI-20-1088
ZDI-20-1089
ZDI-20-1090
ZDI-20-1091
ZDI-20-1092

Affected Products

Iview