CVE-2022-3323 is an SQL injection vulnerability in Advantech iView 5.7.04.6469, specifically within the ConfigurationServlet endpoint. An unauthenticated remote attacker can exploit this flaw by manipulating the column_value parameter in the setConfiguration action, bypassing existing security checks to perform SQL injection and potentially retrieve sensitive information like the iView admin password. This vulnerability is rated as High severity (CVSS 7.5), indicating a network-based attack with low complexity and high impact on confidentiality. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not known to be actively exploited, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.7.04.6469CPE matchmatch criteria | cpe:2.3:a:advantech:iview:5.7.04.6469:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Advantech iView ConfigurationServlet setConfiguration SQL Injection
Sep 26, 2022Advantech iView ConfigurationServlet setConfiguration SQL Injection
Sep 26, 2022Advantech iView ConfigurationServlet setConfiguration SQL Injection
Sep 26, 2022Advantech iView ConfigurationServlet setConfiguration SQL Injection
Sep 26, 2022Advantech iView ConfigurationServlet setConfiguration SQL Injection
Sep 26, 2022