CVE-2023-4203
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD
Description
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface.
Affected (3)
Products: Advantech: Eki 1524 Firmware, Eki 1522 Firmware, Eki 1521 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.24 |
| Running on/with | Platform Versions |
|---|---|
Advantech Eki 1524 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.24 |
| Running on/with | Platform Versions |
|---|---|
Advantech Eki 1522 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.24 |
| Running on/with | Platform Versions |
|---|---|
Advantech Eki 1521 | All versions |
References (6)
Source: office@cyberdanube.com
Source: office@cyberdanube.com
Source: office@cyberdanube.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.