CVE-2023-4202
CRITICALAdvantech EKI-1524, EKI-1522, EKI-1521 <1.21 - XSS
Title source: llmDescription
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.
References (3)
Core 3
Core References
Mailing List
http://seclists.org/fulldisclosure/2023/Aug/13
Exploit, Third Party Advisory
http://packetstormsecurity.com/files/174153/Advantech-EKI-1524-CE-EKI-1522-EKI-1521-Cross-Site-Scripting.html
Exploit, Third Party Advisory third-party-advisory
exploit
https://cyberdanube.com/en/en-st-polten-uas-multiple-vulnerabilities-in-advantech-eki-15xx-series/
Scores
CVSS v3
9.0
EPSS
0.0020
EPSS Percentile
41.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (3)
advantech/eki-1521_firmware
< 1.21
advantech/eki-1522_firmware
< 1.21
advantech/eki-1524_firmware
< 1.21
Published
Aug 08, 2023
Tracked Since
Feb 18, 2026