{"containers":{"cna":{"affected":[{"product":"Advantech iView","vendor":"n/a","versions":[{"status":"affected","version":"Versions 5.6 and prior"}]}],"descriptions":[{"lang":"en","value":"Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"IMPROPER NEUTRALIZATION OF SPECIAL ELEMENTS USED IN AN SQL COMMAND ('SQL INJECTION') CWE-89","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2020-07-16T17:06:49.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"tags":["x_refsource_MISC"],"url":"https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-847/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-827/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-868/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-852/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-862/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-860/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-846/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-844/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-845/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-855/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-857/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-854/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-864/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-849/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-832/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-835/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-848/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-838/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-850/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-856/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-866/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-842/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-837/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-865/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-851/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-828/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-853/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-843/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-839/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-858/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-830/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-861/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-863/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-869/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-833/"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-836/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2020-14497","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Advantech iView","version":{"version_data":[{"version_value":"Versions 5.6 and prior"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"IMPROPER NEUTRALIZATION OF SPECIAL ELEMENTS USED IN AN SQL COMMAND ('SQL INJECTION') CWE-89"}]}]},"references":{"reference_data":[{"name":"https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01","refsource":"MISC","url":"https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-847/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-847/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-827/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-827/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-868/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-868/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-852/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-852/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-862/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-862/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-860/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-860/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-846/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-846/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-844/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-844/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-845/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-845/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-855/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-855/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-857/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-857/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-854/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-854/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-864/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-864/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-849/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-849/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-832/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-832/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-835/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-835/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-848/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-848/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-838/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-838/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-850/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-850/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-856/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-856/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-866/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-866/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-842/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-842/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-837/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-837/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-865/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-865/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-851/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-851/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-828/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-828/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-853/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-853/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-843/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-843/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-839/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-839/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-858/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-858/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-830/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-830/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-861/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-861/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-863/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-863/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-869/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-869/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-833/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-833/"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-20-836/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-20-836/"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T12:46:34.614Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://us-cert.cisa.gov/ics/advisories/icsa-20-196-01"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-847/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-827/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-868/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-852/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-862/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-860/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-846/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-844/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-845/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-855/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-857/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-854/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-864/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-849/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-832/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-835/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-848/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-838/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-850/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-856/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-866/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-842/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-837/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-865/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-851/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-828/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-853/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-843/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-839/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-858/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-830/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-861/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-863/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-869/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-833/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-836/"}]}]},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2020-14497","datePublished":"2020-07-15T01:50:54.000Z","dateReserved":"2020-06-19T00:00:00.000Z","dateUpdated":"2024-08-04T12:46:34.614Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}