Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-22652.
PoCs published by wvu, Spencer McIntyre, including Metasploit module exploits/windows/http/advantech_iview_unauth_rce.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated configuration change and file write vulnerability in Advantech iView, leading to remote code execution as NT AUTHORITY\SYSTEM. It writes a JSP stub to the target system and executes arbitrary commands.
Description
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution.
Exploits (1)
This Metasploit module exploits an unauthenticated configuration change and file write vulnerability in Advantech iView, leading to remote code execution as NT AUTHORITY\SYSTEM. It writes a JSP stub to the target system and executes arbitrary commands.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H