First published: Tue Aug 08 2023(Updated: )
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.
Credit: office@cyberdanube.com office@cyberdanube.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech Eki-1524 Firmware | <=1.21 | |
Advantech EKI-1524 | ||
Advantech Eki-1522 Firmware | <=1.21 | |
Advantech Eki-1522 | ||
Advantech Eki-1521 Firmware | <=1.21 | |
Advantech Eki-1521 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4202 is a Stored Cross-Site Scripting vulnerability affecting Advantech EKI-1524, EKI-1522, and EKI-1521 devices through version 1.21.
CVE-2023-4202 allows authenticated users to trigger a Stored Cross-Site Scripting attack by inserting malicious code into the device name field of the web interface.
CVE-2023-4202 has a severity score of 5.4 (Critical).
To fix the CVE-2023-4202 vulnerability, it is recommended to apply the latest firmware update provided by Advantech.
You can find more information about CVE-2023-4202 on the following references: [1] [2] [3]