// For flags

CVE-2020-14497

Advantech iView TaskEditDeviceTable getTaskEditorSearchDevices SQL Injection Remote Code Execution Vulnerability

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code.

Advantech iView, versiones 5.6 y anteriores, contiene múltiples vulnerabilidades de inyección SQL que son vulnerables al uso de una cadena controlada por el atacante en la construcción de consultas SQL. Un atacante podría extraer las credenciales del usuario, leer o modificar la información y ejecutar el código de forma remota

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the TaskEditDeviceTable class. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.

*Credits: rgod
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-06-19 CVE Reserved
  • 2020-07-15 CVE Published
  • 2024-07-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (37)
URL Tag Source
https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-827 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-828 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-830 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-832 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-833 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-835 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-836 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-837 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-838 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-839 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-842 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-843 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-844 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-845 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-846 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-847 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-848 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-849 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-850 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-851 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-852 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-853 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-854 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-855 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-856 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-857 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-858 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-860 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-861 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-862 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-863 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-864 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-865 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-866 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-868 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-869 Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Advantech
Search vendor "Advantech"
Iview
Search vendor "Advantech" for product "Iview"
<= 5.6
Search vendor "Advantech" for product "Iview" and version " <= 5.6"
-
Affected