ID

VAR-202206-1670


CVE

CVE-2022-2156


TITLE

Advantech iView set_useraccount UserName SQL Injection Remote Code Execution Vulnerability

Trust: 0.7

sources: ZDI: ZDI-22-937

DESCRIPTION

This vulnerability allows remote attackers to create arbitrary files on affected installations of Advantech iView. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.The specific flaw exists within the NetworkServlet endpoint, which listens on TCP port 8080 by default. When parsing the UserName element of the set_useraccount action, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. For the stable distribution (bullseye), these problems have been fixed in version 103.0.5060.53-1~deb11u1. We recommend that you upgrade your chromium packages. For the detailed security status of chromium please refer to its security tracker page at: security-tracker.debian.org/tracker/chromium

Trust: 0.72

sources: ZDI: ZDI-22-937 // VULMON: CVE-2022-2156

AFFECTED PRODUCTS

vendor:advantechmodel:iviewscope: - version: -

Trust: 0.7

sources: ZDI: ZDI-22-937

CVSS

SEVERITY

CVSSV2

CVSSV3

ZDI: CVE-2022-2156
value: HIGH

Trust: 0.7

ZDI: CVE-2022-2156
baseSeverity: HIGH
baseScore: 8.8
vectorString: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-22-937

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202206-2145

PATCH

title:Advantech has issued an update to correct this vulnerability.url:https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-03

Trust: 0.7

title:Google Chrome Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqbyid.tag?id=197132

Trust: 0.6

title:Debian Security Advisories: DSA-5168-1 chromium -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=1df55fca5bc84b333e3feb3ff9ec9e70

Trust: 0.1

title:Google Chrome: Stable Channel Update for Desktopurl:https://vulmon.com/vendoradvisory?qidtp=chrome_releases&qid=f4139027edd7716be086c3c70b2fd7d6

Trust: 0.1

sources: ZDI: ZDI-22-937 // VULMON: CVE-2022-2156 // CNNVD: CNNVD-202206-2145

EXTERNAL IDS

db:NVDid:CVE-2022-2156

Trust: 1.4

db:ZDI_CANid:ZDI-CAN-16773

Trust: 0.7

db:ZDIid:ZDI-22-937

Trust: 0.7

db:AUSCERTid:ESB-2022.3056

Trust: 0.6

db:AUSCERTid:ESB-2022.3066

Trust: 0.6

db:CNNVDid:CNNVD-202206-2145

Trust: 0.6

db:VULMONid:CVE-2022-2156

Trust: 0.1

sources: ZDI: ZDI-22-937 // VULMON: CVE-2022-2156 // CNNVD: CNNVD-202206-2145

REFERENCES

url:https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-03

Trust: 0.7

url:https://vigilance.fr/vulnerability/chrome-multiple-vulnerabilities-38642

Trust: 0.6

url:https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html

Trust: 0.6

url:https://msrc.microsoft.com/update-guide/vulnerability/cve-2022-2156

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.3066

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.3056

Trust: 0.6

url:https://www.debian.org/security/2022/dsa-5168

Trust: 0.1

sources: ZDI: ZDI-22-937 // VULMON: CVE-2022-2156 // CNNVD: CNNVD-202206-2145

CREDITS

rgod

Trust: 0.7

sources: ZDI: ZDI-22-937

SOURCES

db:ZDIid:ZDI-22-937
db:VULMONid:CVE-2022-2156
db:CNNVDid:CNNVD-202206-2145

LAST UPDATE DATE

2022-07-05T22:20:22.607000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-22-937date:2022-06-30T00:00:00
db:CNNVDid:CNNVD-202206-2145date:2022-06-24T00:00:00

SOURCES RELEASE DATE

db:ZDIid:ZDI-22-937date:2022-06-30T00:00:00
db:CNNVDid:CNNVD-202206-2145date:2022-06-21T00:00:00