RULE(RULE ID:333542)

Rule General Information
Release Date: 2021-05-13
Rule Name: Advantech iView DeviceTreeTable exportTaskMgrReport Directory Traversal Vulnerability (CVE-2020-16245)
Severity:
CVE ID:
Rule Protection Details
Description: Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Others
Reference: https://us-cert.cisa.gov/ics/advisories/icsa-20-238-01
ZeroDayInitiative:ZDI-20-1084
ZeroDayInitiative:ZDI-20-1085
ZeroDayInitiative:ZDI-20-1086
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://www.advantech.tw/support/details/faq?id=1-HIPU-181