First published: Sun Feb 21 2016(Updated: )
The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to perform administrative actions via modified JavaScript code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech Vesp211-eu | ||
Advantech Vesp211-eu Firmware | =1.7.2 | |
Advantech Vesp211-232 | ||
Advantech Vesp211-232 Firmware | =1.5.1 | |
Advantech Vesp211-232 Firmware | =1.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.