← Vulnerability feed

Vulnerability record · CVE-2022-2139 · published 22 July 2022

CVE-2022-2139: Advantech iview relative path traversal vulnerability

Advantech · Iview

The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.

9.8 CVSS 3.1 Critical EPSS 16% · top 3.3% CWE-23 · Relative path traversalCWE-22 · Path traversal
9.8CVSS 3.1 base score
16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-03 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-03 Third Party AdvisoryUS Government Resource

Track CVE-2022-2139 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-2143Advantech iView command injection in NetworkServletAdvantech iView contains two command injection flaws (CWE-77) that let an attacker run arbitrary commands on the host. The vulnerability is remotely …EPSS 59%analysed9.8CVE-2021-32930Advantech iview missing authentication for critical function vulnerabilityThe affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute ar…EPSS 8.1%9.8CVE-2021-22652Advantech iview missing authentication for critical function vulnerabilityAccess to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to ch…EPSS 37%9.8CVE-2021-22658Advantech iview sql injection vulnerabilityAdvantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrato…EPSS 13%9.8CVE-2020-16245Advantech iview path traversal vulnerabilityAdvantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/…EPSS 7.7%9.8CVE-2020-14501Advantech iview missing authentication for critical function vulnerabilityAdvantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulner…EPSS 1.7%9.8CVE-2020-14503Advantech iview improper input validation vulnerabilityAdvantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this vulnerability could allow an…EPSS 3.5%9.8CVE-2020-14497Advantech iview sql injection vulnerabilityAdvantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled str…EPSS 4.9%

Source: NIST National Vulnerability Database (record CVE-2022-2139), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.