CVE-2024-38308: Advantech ADAM-5550 Cross-site Scripting
Published Sep 27, 2024
·Updated
Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.
Affected Software
2 affected components
All of the following
Advantech Adam 5550-firmware
Advantech ADAM-5550
Remediation
Information
ADAM-5550 is currently being phased out, and Advantech strongly
recommends all ADAM-5550 users upgrade to ADAM-5630 firmware version
2.5.2 or higher.
Event History
Sep 27, 2024
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38308?
CVE-2024-38308 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-38308?
To fix CVE-2024-38308, ensure you apply the latest firmware updates from Advantech for the ADAM 5550.
3
What products are affected by CVE-2024-38308?
CVE-2024-38308 affects the Advantech ADAM 5550's web application.
4
What type of vulnerability is CVE-2024-38308?
CVE-2024-38308 is a code injection vulnerability that can allow the execution of malicious code through improperly parsed HTTP requests.
5
Can CVE-2024-38308 be exploited remotely?
Yes, CVE-2024-38308 can be exploited remotely through malicious HTTP requests directed at the web application.