The specific flaw exists within the ConfigurationServlet servlet, which listens on TCP port 8080 by default. When parsing the column_value element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-17863.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-56992 | Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ConfigurationServlet servlet, which listens on TCP port 8080 by default. When parsing the column_value element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-17863. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 09 Jan 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:advantech:iview:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 05 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Advantech
Advantech iview |
|
| CPEs | cpe:2.3:a:advantech:iview:5.7.04:*:*:*:*:*:*:* | |
| Vendors & Products |
Advantech
Advantech iview |
|
| Metrics |
ssvc
|
Fri, 22 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ConfigurationServlet servlet, which listens on TCP port 8080 by default. When parsing the column_value element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-17863. | |
| Title | Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2024-12-05T19:32:34.015Z
Reserved: 2024-01-11T20:39:58.816Z
Link: CVE-2023-52335
Updated: 2024-12-05T19:32:25.125Z
Status : Analyzed
Published: 2024-11-22T20:15:07.927
Modified: 2025-01-09T16:05:53.673
Link: CVE-2023-52335
No data.
OpenCVE Enrichment
No data.
EUVD