VulnerabilityModified
CVE-2021-22652
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution.
CRITICAL 9.8EPSS 36.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 36.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 36.84% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- advantech/iview
- Source
- ics-cert@hq.dhs.gov
References
- http://packetstormsecurity.com/files/161937/Advantech-iView-Unauthenticated-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://us-cert.cisa.gov/ics/advisories/icsa-21-040-02Third Party Advisory, US Government Resource
- http://packetstormsecurity.com/files/161937/Advantech-iView-Unauthenticated-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://us-cert.cisa.gov/ics/advisories/icsa-21-040-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.