PT-2022-6139 · Advantech · Advantech Iview

Rgod

·

Published

2022-03-23

·

Updated

2022-07-29

·

CVE-2022-2139

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech iView (affected versions not specified)
Description The issue is related to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code. The vulnerability is associated with incorrect restriction of the path name to a directory with limited access when processing the MenuServlet endpoint. Exploitation of the vulnerability may allow a remote attacker to gain unauthorized access to protected information or execute arbitrary code by connecting to port 8080/TCP.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00155
CVE-2022-2139
ZDI-22-931
ZDI-22-932
ZDI-22-933

Affected Products

Advantech Iview