Vulnerability Description
Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advantech | Iview | <= 5.6 |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01Third Party AdvisoryUS Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-20-827/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-828/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-830/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-832/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-833/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-835/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-836/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-837/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-838/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-839/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-842/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-843/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-844/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-845/Third Party Advisory
FAQ
What is CVE-2020-14497?
CVE-2020-14497 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker...
How severe is CVE-2020-14497?
CVE-2020-14497 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-14497?
Check the references section above for vendor advisories and patch information. Affected products include: Advantech Iview.