CVE-2020-14505
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
15/07/2020
Last modified:
22/07/2020
Description
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command string without any validation. The attacker may then remotely execute code.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:advantech:iview:*:*:*:*:*:*:*:* | 5.6 (including) |
To consult the complete list of CPE names with products and versions, see this page



