CVE-2024-50358: High severity Advantech EKI-6333AC-2G vulnerability
A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by authenticated users by restoring a tampered configuration backup.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50358?
The severity of CVE-2024-50358 is classified as high due to the potential for unauthorized configuration changes by authenticated users.
How do I fix CVE-2024-50358?
To mitigate CVE-2024-50358, users should update affected Advantech devices to versions later than EKI-6333AC-2G v1.6.3, EKI-6333AC-2GD v1.6.3, or EKI-6333AC-1GPO v1.2.1.
Who is affected by CVE-2024-50358?
CVE-2024-50358 affects Advantech EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO devices running specific versions.
What type of vulnerability is CVE-2024-50358?
CVE-2024-50358 is classified as an External Control of System or Configuration Setting vulnerability.
Can CVE-2024-50358 be exploited remotely?
CVE-2024-50358 cannot be exploited remotely as it requires authenticated user access to exploit the vulnerability.