CVE-2023-2573: Authenticated Command Injection
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this command injection vulnerability?
The vulnerability ID for this command injection vulnerability is CVE-2023-2573.
Which devices are affected by this command injection vulnerability?
Advantech EKI-1524, EKI-1522, and EKI-1521 devices through version 1.21 are affected by this command injection vulnerability.
How can this command injection vulnerability be triggered?
This command injection vulnerability can be triggered by authenticated users via a crafted POST request in the NTP server input field.
What is the severity rating of CVE-2023-2573?
CVE-2023-2573 has a severity rating of 8.8 (high).
Are there any fixes available for this command injection vulnerability?
Yes, Advantech has released firmware updates to address this command injection vulnerability. Refer to the manufacturer's support website for the appropriate firmware update.