Description
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Install firmware 1.24 to fix the issue.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-34052 | Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request. |
References
History
Thu, 13 Feb 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request. | Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request. |
Wed, 29 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: CyberDanube
Published:
Updated: 2025-02-13T16:44:36.399Z
Reserved: 2023-05-08T11:13:35.330Z
Link: CVE-2023-2574
Updated: 2024-08-02T06:26:09.703Z
Status : Modified
Published: 2023-05-08T13:15:09.790
Modified: 2025-02-13T17:16:21.543
Link: CVE-2023-2574
No data.
OpenCVE Enrichment
No data.
EUVD