Advantech
Advantech Iview: vulnerabilidades y CVE
Advantech Iview tiene 39 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses6
Críticas14
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-13373 | Alta (8.7) | 0.44% | — | 4 dic 2025 | Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands. |
| CVE-2022-50595 | Crítica (9.3) | 0.63% | — | 6 nov 2025 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability… |
| CVE-2022-50594 | Alta (8.8) | 0.46% | — | 6 nov 2025 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability… |
| CVE-2022-50593 | Crítica (9.3) | 0.69% | — | 6 nov 2025 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability… |
| CVE-2022-50592 | Crítica (9.3) | 0.63% | — | 6 nov 2025 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability… |
| CVE-2022-50591 | Alta (8.8) | 0.50% | — | 6 nov 2025 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability… |
| CVE-2025-53519 | Media (5.1) | 0.21% | — | 11 jul 2025 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized… |
| CVE-2025-53515 | Alta (8.7) | 0.57% | — | 11 jul 2025 | A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges.… |
| CVE-2025-53509 | Alta (7.1) | 0.32% | — | 11 jul 2025 | A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. An input parameter… |
| CVE-2025-53475 | Alta (8.7) | 6.1% | — | 11 jul 2025 | A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level… |
| CVE-2025-53397 | Media (5.1) | 0.21% | — | 11 jul 2025 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in… |
| CVE-2025-52577 | Alta (8.7) | 0.57% | — | 11 jul 2025 | A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at least user-level… |
| CVE-2025-52459 | Alta (7.1) | 0.31% | — | 11 jul 2025 | A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can… |
| CVE-2025-48891 | Alta (7.2) | 0.29% | — | 11 jul 2025 | A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level… |
| CVE-2025-46704 | Media (5.3) | 4.7% | — | 11 jul 2025 | A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A… |
| CVE-2025-41442 | Media (5.1) | 0.21% | — | 11 jul 2025 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute… |
| CVE-2023-52335 | Alta (7.5) | 1.3% | — | 22 nov 2024 | Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView.… |
| CVE-2023-3983 | Alta (8.8) | 17% | — | 31 jul 2023 | An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform… |
| CVE-2022-3323 | Alta (7.5) | 29% | — | 27 sept 2022 | An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a… |
| CVE-2022-2143 | Crítica (9.8) | 59% | — | 22 jul 2022 | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. |
| CVE-2022-2142 | Media (5.9) | 0.89% | — | 22 jul 2022 | The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attacker to disclose information. |
| CVE-2022-2139 | Crítica (9.8) | 16% | — | 22 jul 2022 | The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code. |
| CVE-2022-2138 | Alta (7.5) | 11% | — | 22 jul 2022 | The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition. |
| CVE-2022-2137 | Media (4.9) | 0.94% | — | 22 jul 2022 | The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information |
| CVE-2022-2136 | Media (6.5) | 9.1% | — | 22 jul 2022 | The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information. |
| CVE-2022-2135 | Alta (7.5) | 10% | — | 22 jul 2022 | The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information. |
| CVE-2021-32932 | Alta (7.5) | 1.2% | — | 11 jun 2021 | The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182). |
| CVE-2021-32930 | Crítica (9.8) | 8.1% | — | 11 jun 2021 | The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arbitrary code on the iView (versions prior to v5.7.03.6182). |
| CVE-2021-22658 | Crítica (9.8) | 13% | — | 11 feb 2021 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'. |
| CVE-2021-22656 | Alta (7.5) | 3.2% | — | 11 feb 2021 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files. |