CVE-2023-4202: Stored Cross-Site Scripting
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4202?
CVE-2023-4202 is a Stored Cross-Site Scripting vulnerability affecting Advantech EKI-1524, EKI-1522, and EKI-1521 devices through version 1.21.
How does CVE-2023-4202 impact the affected devices?
CVE-2023-4202 allows authenticated users to trigger a Stored Cross-Site Scripting attack by inserting malicious code into the device name field of the web interface.
What is the severity of CVE-2023-4202?
CVE-2023-4202 has a severity score of 5.4 (Critical).
How can I fix the CVE-2023-4202 vulnerability?
To fix the CVE-2023-4202 vulnerability, it is recommended to apply the latest firmware update provided by Advantech.
Where can I find more information about CVE-2023-4202?
You can find more information about CVE-2023-4202 on the following references: [1] [2] [3]