CVE-2022-3323
Last modified
CVE-2022-3323 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. EPSS estimates a 30.67% chance of exploitation in the next 30 days.
Description
An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Advantech | Iview | 5.7.04.6469 |
References
- https://www.tenable.com/security/research/tra-2022-32Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2022-32Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3323?
How severe is CVE-2022-3323?
How do I fix CVE-2022-3323?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-33224Memory corruption in core due to buffer copy without check9i…7.8
- CVE-2022-33225Memory corruption due to use after free in trusted applicati…7.8
- CVE-2022-33226Memory corruption due to buffer copy without checking the si…7.8
- CVE-2022-33227Memory corruption in Linux android due to double free while …7.8
- CVE-2022-33228Information disclosure sue to buffer over-read in modem whil…7.5
- CVE-2022-33229Information disclosure due to buffer over-read in Modem whil…7.5
- CVE-2022-33230Memory corruption in FM Host due to buffer copy without chec…7.8
- CVE-2022-33231Memory corruption due to double free in core while initializ…7.8
- CVE-2022-33232Memory corruption due to buffer copy without checking size o…7.8
- CVE-2022-33233Memory corruption due to configuration weakness in modem wil…7.8
- CVE-2022-33234Memory corruption in video due to configuration weakness. in…9.8
- CVE-2022-33235Information disclosure due to buffer over-read in WLAN firmw…7.5
Are you affected by CVE-2022-3323?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
