Advantech Vulnerabilities and Affected Products
Vulnerabilities associated with EKI-1521.
Products
Clear product- WebAccess31 vulnerabilities
- EKI-6333AC-1GPO20 vulnerabilities
- EKI-6333AC-2G20 vulnerabilities
- EKI-6333AC-2GD20 vulnerabilities
- eki-6333ac-1gpo_firmware19 vulnerabilities
- eki-6333ac-2g_firmware19 vulnerabilities
- eki-6333ac-2gd_firmware19 vulnerabilities
- iView17 vulnerabilities
- WebAccess/SCADA16 vulnerabilities
- WebAccess/VPN12 vulnerabilities
- Advantech WebAccess9 vulnerabilities
- Advantech Wireless Sensing and Equipment (WISE)8 vulnerabilities
- R-SeeNet8 vulnerabilities
- EKI-15215 vulnerabilities
- EKI-15225 vulnerabilities
- EKI-15245 vulnerabilities
- ADAM-56304 vulnerabilities
- DeviceOn/iEdge4 vulnerabilities
- ADAM 55502 vulnerabilities
- adam-5630_firmware2 vulnerabilities
- HMI Designer2 vulnerabilities
- ADAM-36001 vulnerability
- ECOWatch SaaS-Composer1 vulnerability
- Hospital Quering Management1 vulnerability
- Hospital Queuing Management1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-4203CRITICAL | Stored Cross-Site ScriptingAdvantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface. CWE-79Aug 8, 2023 | CVSS9.0v3.1 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4202CRITICAL | Stored Cross-Site ScriptingAdvantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface. CWE-79Aug 8, 2023 | CVSS9.0v3.1 | EPSS0.975% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2573HIGH | Authenticated Command InjectionAdvantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request. | CVSS8.8v3.1 | EPSS4.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2574HIGH | Authenticated Command InjectionAdvantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request. | CVSS8.8v3.1 | EPSS4.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2575HIGH | Authenticated Buffer OverflowAdvantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request. | CVSS8.8v3.1 | EPSS15.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |