CVE-2024-28948

HIGH

Advantech ADAM-5630 Firmware < 2.5.2 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02

Scores

CVSS v3 8.0
EPSS 0.0009
EPSS Percentile 24.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (1)
advantech/adam-5630_firmware < 2.5.2
Published Sep 27, 2024
Tracked Since Feb 18, 2026