First published: Fri Sep 27 2024(Updated: )
Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Advantech Adam-5630 Firmware | <2.5.2 | |
Advantech Adam-5630 Firmware |
Advantech recommends users upgrade their ADAM-5630 devices to version 2.5.2 https://www.advantech.com/zh-tw/support/details/firmware .
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28948 is classified as a medium severity vulnerability due to its ability to exploit the CSRF weakness.
To fix CVE-2024-28948, update the Advantech ADAM-5630 firmware to version 2.5.2 or later.
CVE-2024-28948 is a cross-site request forgery (CSRF) vulnerability.
CVE-2024-28948 may allow attackers to bypass the same origin policy, leading to unauthorized actions on behalf of users.
CVE-2024-28948 affects Advantech ADAM-5630 devices running firmware versions earlier than 2.5.2.