CVE Database
/

CVE-2020-14505

Back to search

CVE-2020-14505

Published: Jul 15, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command string without any validation. The attacker may then remotely execute code.

VendorProductVersions

n/a

Advantech iView

affected
Versions 5.6 and prior

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now