First published: Mon May 08 2023(Updated: )
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.
Credit: office@cyberdanube.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech Eki-1521 Firmware | <=1.21 | |
Advantech Eki-1521 | ||
Advantech Eki-1522 Firmware | <=1.21 | |
Advantech Eki-1522 | ||
Advantech Eki-1524 Firmware | <=1.21 | |
Advantech EKI-1524 |
Install firmware 1.24 to fix the issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2574 is a command injection vulnerability affecting Advantech EKI-1524, EKI-1522, and EKI-1521 devices through firmware version 1.21.
Authenticated users can exploit CVE-2023-2574 by sending crafted POST requests to the device name input field.
Yes, Advantech EKI-1521 firmware through version 1.21 is affected by CVE-2023-2574.
Yes, Advantech has released firmware updates to address CVE-2023-2574. Please refer to the vendor's support page for more information.
CVE-2023-2574 has a severity score of 8.8 (high).