CVE-2023-4203: Stored Cross-Site Scripting
Published Aug 8, 2023
·Updated
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface.
Affected Software
12 affected components
All of the following
Advantech Eki-1524 Firmware<=1.24
Advantech EKI-1524
All of the following
Advantech Eki-1522 Firmware<=1.24
Advantech EKI-1522
All of the following
Advantech Eki-1521 Firmware<=1.24
Advantech EKI-1521
Advantech Eki-1524 Firmware<=1.24
Advantech EKI-1524
Advantech Eki-1522 Firmware<=1.24
Advantech EKI-1522
Advantech Eki-1521 Firmware<=1.24
Advantech EKI-1521
Event History
Aug 8, 2023
CVE Published
via MITRE·10:29 AM
Data Sourced
via MITRE·10:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-4203.
2
What is the severity of CVE-2023-4203?
CVE-2023-4203 has a severity rating of 5.4 (critical).
3
Which devices are affected by CVE-2023-4203?
Advantech EKI-1524, EKI-1522, and EKI-1521 devices with firmware up to version 1.24 are affected by this vulnerability.
4
How can the vulnerability be triggered?
The vulnerability can be triggered by authenticated users in the ping tool of the web interface.
5
Is there a fix available for CVE-2023-4203?
It is recommended to update the firmware to a version higher than 1.24 to mitigate CVE-2023-4203.