PT-2020-14838 · Advantech · Iview
Published
2020-08-25
·
Updated
2020-08-31
·
CVE-2020-16245
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Advantech iView versions 5.7 and prior
Description
The affected product is vulnerable to path traversal vulnerabilities, which could allow an attacker to create or download arbitrary files, limit system availability, and remotely execute code. The vulnerability affects various components, including the DeviceTreeTable, NetworkServlet, TaskMgrTable, and PSTable, allowing for directory traversal, remote code execution, and information disclosure.
Recommendations
For versions 5.7 and prior, update to a version later than 5.7 to resolve the issue.
As a temporary workaround, consider restricting access to the affected components, such as the DeviceTreeTable, NetworkServlet, TaskMgrTable, and PSTable, to minimize the risk of exploitation.
Avoid using the affected API endpoints, such as
DeviceTreeTable exportTaskMgrReport, NetworkServlet findCfgDeviceListExport, DeviceTreeTable exportInventoryTable, NetworkServlet findSummaryCfgDeviceListExport, TaskMgrTable exportTaskMgrReportDetails, NetworkServlet findUpdateDeviceListExport, NetworkServlet backupDatabase, NetworkServlet findSummaryUpdateDeviceListExport, and PSTable exportPSInventoryTable, until the issue is resolved.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iview