Home/Product/advantech iview
Product

advantech iview

38 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-50595
< 5.7.04.6425
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for rem
7.2HIGH
CVE-2022-50594
< 5.7.04.6425
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for rem
7.5HIGH
CVE-2022-50593
< 5.7.04.6425
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for rem
9.8CRITICAL
CVE-2022-50592
< 5.7.04.6425
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for rem
7.2HIGH
CVE-2022-50591
< 5.7.04.6425
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for rem
9.8CRITICAL
CVE-2025-53519
< 5.7.05.7057
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting
5.4MEDIUM
CVE-2025-53515
< 5.7.05.7057
A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveT
8.8HIGH
CVE-2025-53509
< 5.7.05.7057
A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue
6.5MEDIUM
CVE-2025-53475
< 5.7.05.7057
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.ge
8.8HIGH
CVE-2025-53397
< 5.7.05.7057
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting
5.4MEDIUM
CVE-2025-52577
< 5.7.05.7057
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archive
8.8HIGH
CVE-2025-48891
< 5.7.05.7057
A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. Thi
7.6HIGH
CVE-2025-46704
< 5.7.05.7057
A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal at
4.3MEDIUM
CVE-2025-41442
< 5.7.05.7057
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting
5.4MEDIUM
CVE-2023-52335
< 5.7.04.6752
Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attacker
7.5HIGH
CVE-2023-3983
< 5.7.4.6752
An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remot
8.8HIGH
CVE-2023-33335
all versions
Cross Site Scripting (XSS) in Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary scri
6.1MEDIUM
CVE-2022-3323
all versions
An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint,
7.5HIGH
CVE-2022-2143
< 5.7.04.6469
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrar
9.8CRITICAL
CVE-2022-2142
< 5.7.04.6469
The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attacker to dis
8.1HIGH
CVE-2022-2139
< 5.7.04.6469
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute ar
6.5MEDIUM
CVE-2022-2138
< 5.7.04.6469
The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and
8.2HIGH
CVE-2022-2137
< 5.7.04.6469
The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthoriz
4.9MEDIUM
CVE-2022-2136
< 5.7.04.6469
The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauth
8.8HIGH
CVE-2022-2135
< 5.7.04.6469
The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information.
7.5HIGH
CVE-2021-32932
< 5.7.03.6182
The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iVi
7.5HIGH
CVE-2021-32930
< 5.7.03.6182
The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configur
9.8CRITICAL
CVE-2021-22658
< 5.7.03.6112
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileg
9.8CRITICAL
CVE-2021-22656
< 5.7.03.6112
Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitiv
7.5HIGH
CVE-2021-22654
< 5.7.03.6112
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disc
7.5HIGH
CVE-2021-22652
< 5.7.03.6112
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthor
9.8CRITICAL
CVE-2020-16245
<= 5.7
Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an
9.8CRITICAL
CVE-2020-14503
<= 5.6
Advantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this vulnerabi
9.8CRITICAL
CVE-2020-14501
<= 5.6
Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploita
9.8CRITICAL
CVE-2020-14499
<= 5.6
Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerabili
7.5HIGH
CVE-2020-14507
<= 5.6
Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to
9.8CRITICAL
CVE-2020-14505
<= 5.6
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injectio
9.8CRITICAL
CVE-2020-14497
<= 5.6
Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an atta
9.8CRITICAL
threatengine.sh