Advantech

Iview

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.72%
  • Veröffentlicht 22.07.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:24

The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attacker to disclose information.

  • EPSS 14.83%
  • Veröffentlicht 22.07.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:24

The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.

  • EPSS 10.92%
  • Veröffentlicht 22.07.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:24

The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition.

  • EPSS 0.75%
  • Veröffentlicht 22.07.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:24

The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information

  • EPSS 9%
  • Veröffentlicht 22.07.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:24

The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information.

  • EPSS 10.09%
  • Veröffentlicht 22.07.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:24

The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information.

  • EPSS 1.17%
  • Veröffentlicht 11.06.2021 17:15:11
  • Zuletzt bearbeitet 21.11.2024 06:07:57

The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182).

  • EPSS 8.06%
  • Veröffentlicht 11.06.2021 17:15:10
  • Zuletzt bearbeitet 21.11.2024 06:07:56

The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arbitrary code on the iView (versions prior to v5.7.03.6182).

  • EPSS 12.72%
  • Veröffentlicht 11.02.2021 18:15:17
  • Zuletzt bearbeitet 21.11.2024 05:50:25

Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'.

Exploit
  • EPSS 36.85%
  • Veröffentlicht 11.02.2021 18:15:17
  • Zuletzt bearbeitet 21.11.2024 05:50:23

Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution.