CVE-2023-2574: Authenticated Command Injection
Published May 8, 2023
·Updated
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.
Affected Software
12 affected components
All of the following
Advantech Eki-1521 Firmware<=1.21
Advantech EKI-1521
All of the following
Advantech Eki-1522 Firmware<=1.21
Advantech EKI-1522
All of the following
Advantech Eki-1524 Firmware<=1.21
Advantech EKI-1524
Advantech Eki-1521 Firmware<=1.21
Advantech EKI-1521
Advantech Eki-1522 Firmware<=1.21
Advantech EKI-1522
Advantech Eki-1524 Firmware<=1.21
Advantech EKI-1524
Remediation
Information
Install firmware 1.24 to fix the issue.
Event History
May 8, 2023
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
01:15 PM
Description
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-2574?
CVE-2023-2574 is a command injection vulnerability affecting Advantech EKI-1524, EKI-1522, and EKI-1521 devices through firmware version 1.21.
2
How can authenticated users exploit CVE-2023-2574?
Authenticated users can exploit CVE-2023-2574 by sending crafted POST requests to the device name input field.
3
Is Advantech EKI-1521 firmware affected by CVE-2023-2574?
Yes, Advantech EKI-1521 firmware through version 1.21 is affected by CVE-2023-2574.
4
Is there a fix for CVE-2023-2574?
Yes, Advantech has released firmware updates to address CVE-2023-2574. Please refer to the vendor's support page for more information.
5
What is the severity of CVE-2023-2574?
CVE-2023-2574 has a severity score of 8.8 (high).