CVE-2019-18235

CRITICAL

Advantech Spectre RT ERT351 Firmware <= 5.1.3 - Unauthenticated Brute-Force Login

Title source: llm
STIX 2.1

Description

Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-054-03

Scores

CVSS v3 9.8
EPSS 0.0039
EPSS Percentile 59.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-307
Status published
Products (1)
advantech/spectre_rt_ert351_firmware < 5.1.3
Published Mar 17, 2021
Tracked Since Feb 18, 2026