CVE detail
CVE-2020-14505 — CVE-2020-14505
Published 2020-07-15 · Modified 2026-06-17 · Vendor advantech · Product iview · Source nvd
CRITICAL
severity
CVSS-derived band
0.0702
EPSS probability
exploitation probability, 30d
94.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command string without any validation. The attacker may then remotely execute code.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References