PT-2021-19980 · Advantech · Advantech Iview

Enesdex

·

Published

2021-06-07

·

Updated

2021-06-21

·

CVE-2021-32932

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Advantech iView versions prior to v5.7.03.6182
Description The issue allows an unauthorized attacker to disclose information due to a SQL injection vulnerability. It affects various functions, including findUpdateDeviceListDetails, saveZtpConfig, deleteZtpConfig, getInventoryReportData, getAllActiveTraps, setDeviceAuthentication, getNextTrapPage, and getPSInventoryInfo in the NetworkServlet.
Recommendations For versions prior to v5.7.03.6182, update to version v5.7.03.6182 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable functions until a patch is available. Avoid using the vulnerable NetworkServlet endpoints, such as /NetworkServlet, until the issue is resolved. Restrict access to the SQL database to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32932
ZDI-21-649
ZDI-21-650
ZDI-21-651
ZDI-21-652
ZDI-21-653
ZDI-21-654
ZDI-21-655
ZDI-21-656

Affected Products

Advantech Iview