CVE-2022-50592 is a high-severity vulnerability affecting Advantech iView versions prior to v5.7.04 build 6425, specifically within its SNMP management tool. It allows remote attackers to bypass authentication and exploit a SQL injection in the 'getInventoryReportData' parameter of the 'NetworkServlet' endpoint. Successful exploitation can lead to remote code execution with administrator privileges. The CVSS score is 7.2 (HIGH), indicating a network-based attack with low complexity and high impact on confidentiality, integrity, and availability. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB) and no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.7.04.6425CPE matchmatch criteria | cpe:2.3:a:advantech:iview:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.