Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code.
References
Link Providers
https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01 cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-827/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-828/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-830/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-832/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-833/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-835/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-836/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-837/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-838/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-839/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-842/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-843/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-844/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-845/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-846/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-847/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-848/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-849/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-850/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-851/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-852/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-853/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-854/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-855/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-856/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-857/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-858/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-860/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-861/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-862/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-863/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-864/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-865/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-866/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-868/ cve-icon cve-icon
https://www.zerodayinitiative.com/advisories/ZDI-20-869/ cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2020-07-15T01:50:54

Updated: 2024-08-04T12:46:34.614Z

Reserved: 2020-06-19T00:00:00

Link: CVE-2020-14497

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-07-15T02:15:12.547

Modified: 2020-07-21T20:34:07.950

Link: CVE-2020-14497

cve-icon Redhat

No data.