SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22652

Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution.

CRITICAL 9.8EPSS 36.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 36.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
36.84% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
advantech/iview
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.