Unrated severityNVD Advisory· Published Jul 15, 2020· Updated Aug 4, 2024
CVE-2020-14505
CVE-2020-14505
Description
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command string without any validation. The attacker may then remotely execute code.
Affected products
1- Range: Versions 5.6 and prior
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- us-cert.cisa.gov/ics/advisories/icsa-20-196-01mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-20-831/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.