First published: Tue Aug 08 2023(Updated: )
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface.
Credit: office@cyberdanube.com office@cyberdanube.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech Eki-1524 Firmware | <=1.24 | |
Advantech EKI-1524 | ||
Advantech Eki-1522 Firmware | <=1.24 | |
Advantech Eki-1522 | ||
Advantech Eki-1521 Firmware | <=1.24 | |
Advantech Eki-1521 | ||
All of | ||
Advantech Eki-1524 Firmware | <=1.24 | |
Advantech EKI-1524 | ||
All of | ||
Advantech Eki-1522 Firmware | <=1.24 | |
Advantech Eki-1522 | ||
All of | ||
Advantech Eki-1521 Firmware | <=1.24 | |
Advantech Eki-1521 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-4203.
CVE-2023-4203 has a severity rating of 5.4 (critical).
Advantech EKI-1524, EKI-1522, and EKI-1521 devices with firmware up to version 1.24 are affected by this vulnerability.
The vulnerability can be triggered by authenticated users in the ping tool of the web interface.
It is recommended to update the firmware to a version higher than 1.24 to mitigate CVE-2023-4203.