CVE-2022-2142
- EPSS 0.19%
- Veröffentlicht 22.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:24
The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attacker to disclose information.
CVE-2022-2139
- EPSS 0.47%
- Veröffentlicht 22.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:24
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.
CVE-2022-2138
- EPSS 0.17%
- Veröffentlicht 22.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:24
The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition.
CVE-2022-2137
- EPSS 0.2%
- Veröffentlicht 22.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:24
The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information
CVE-2022-2136
- EPSS 0.18%
- Veröffentlicht 22.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:24
The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information.
CVE-2022-2135
- EPSS 0.2%
- Veröffentlicht 22.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:24
The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information.
CVE-2021-32932
- EPSS 0.19%
- Veröffentlicht 11.06.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 06:07:57
The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182).
CVE-2021-32930
- EPSS 0.45%
- Veröffentlicht 11.06.2021 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:07:56
The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arbitrary code on the iView (versions prior to v5.7.03.6182).
CVE-2021-22658
- EPSS 0.33%
- Veröffentlicht 11.02.2021 18:15:17
- Zuletzt bearbeitet 21.11.2024 05:50:25
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'.
CVE-2021-22652
- EPSS 40.86%
- Veröffentlicht 11.02.2021 18:15:17
- Zuletzt bearbeitet 21.11.2024 05:50:23
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution.