← Vulnerability feed

Vulnerability record · CVE-2022-2143 · published 22 July 2022

CVE-2022-2143: Advantech iView command injection in NetworkServlet

Advantech · Iview

Advantech iView contains two command injection flaws (CWE-77) that let an attacker run arbitrary commands on the host. The vulnerability is remotely reachable with no authentication or user interaction, and a public exploit exists, so it is a serious risk for any exposed iView instance.

9.8 CVSS 3.1 Critical EPSS 59% · top 0.9% CWE-77 · Command injection
9.8CVSS 3.1 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code available, and a very high EPSS score make this an urgent patching priority.

What it is

Advantech iView contains two command injection flaws (CWE-77) that let an attacker run arbitrary commands on the host. The vulnerability is remotely reachable with no authentication or user interaction, and a public exploit exists, so it is a serious risk for any exposed iView instance.

Impact

An unauthenticated remote attacker can execute arbitrary code with the privileges of the iView service, leading to full compromise of the affected host.

Attack surface

Reached over the network via the iView NetworkServlet HTTP interface; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication or user interaction is required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.594 (99th percentile) and public exploit code is referenced on Packet Storm, indicating active interest and readily available exploitation.

What to do

  • Apply the vendor fix referenced in CISA ICS advisory ICSA-22-179-03 as the first action.
  • Restrict network access to the iView web interface to trusted management networks only.
  • Do not expose iView directly to the internet; place it behind a firewall or VPN.
  • Monitor and review logs for unexpected command execution or unusual child processes spawned by the iView service.
  • If patching is not immediately possible, isolate affected systems until remediation is complete.

Detection

  • Inspect web server and application logs for suspicious requests to NetworkServlet endpoints.
  • Monitor for unexpected child processes (cmd.exe, /bin/sh) spawned by the iView service.
  • Alert on outbound network connections from iView hosts to unknown destinations.
  • Use file integrity monitoring on iView installation directories to catch dropped payloads.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-2143 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-2139Advantech iview relative path traversal vulnerabilityThe affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.EPSS 16%9.8CVE-2021-32930Advantech iview missing authentication for critical function vulnerabilityThe affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute ar…EPSS 8.1%9.8CVE-2021-22652Advantech iview missing authentication for critical function vulnerabilityAccess to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to ch…EPSS 37%9.8CVE-2021-22658Advantech iview sql injection vulnerabilityAdvantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrato…EPSS 13%9.8CVE-2020-16245Advantech iview path traversal vulnerabilityAdvantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/…EPSS 7.7%9.8CVE-2020-14501Advantech iview missing authentication for critical function vulnerabilityAdvantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulner…EPSS 1.7%9.8CVE-2020-14503Advantech iview improper input validation vulnerabilityAdvantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this vulnerability could allow an…EPSS 3.5%9.8CVE-2020-14497Advantech iview sql injection vulnerabilityAdvantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled str…EPSS 4.9%

Source: NIST National Vulnerability Database (record CVE-2022-2143), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.