Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulnerability may allow an attacker to obtain the information of the user table, including the administrator credentials in plain text. An attacker may also delete the administrator account.
Advantech iView, versiones 5.6 y anteriores, tiene un problema de autenticación inadecuada para la función crítica (CWE-306). El aprovechamiento satisfactorio de esta vulnerabilidad puede permitir a un atacante obtener la información de la tabla de usuarios, incluidas las credenciales de administrador en texto plano. Un atacante también puede eliminar la cuenta del administrador
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the UserServlet class. The issue results from the lack of authentication prior to allowing alterations to the system configuration. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.