VYPR
High severity7.5NVD Advisory· Published Sep 27, 2022· Updated Jun 17, 2026

CVE-2022-3323

CVE-2022-3323

Description

An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Advantech/iView2 versions
    cpe:2.3:a:advantech:iview:5.7.04.6469:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:advantech:iview:5.7.04.6469:*:*:*:*:*:*:*
    • (no CPE)range: 5.7.04.6469

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.