Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01 | third party advisory us government resource |
https://www.zerodayinitiative.com/advisories/ZDI-20-867/ | vdb entry third party advisory |