Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-6633 Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01 cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-827/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-828/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-830/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-832/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-833/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-835/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-836/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-837/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-838/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-839/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-842/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-843/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-844/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-845/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-846/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-847/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-848/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-849/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-850/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-851/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-852/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-853/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-854/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-855/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-856/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-857/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-858/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-860/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-861/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-862/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-863/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-864/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-865/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-866/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-868/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-869/ cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-04T12:46:34.614Z

Reserved: 2020-06-19T00:00:00

Link: CVE-2020-14497

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-15T02:15:12.547

Modified: 2024-11-21T05:03:23.890

Link: CVE-2020-14497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.