Show filters
325 Total Results
Displaying 21-30 of 325
Sort by:
Attacker Value
Unknown

CVE-2024-50361

Disclosure Date: November 26, 2024 (last updated January 05, 2025)
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "certificate_file_remove" API which are not properly sanitized before being concatenated to OS level commands.
0
Attacker Value
Unknown

CVE-2024-50360

Disclosure Date: November 26, 2024 (last updated January 05, 2025)
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "snmp_apply" API which are not properly sanitized before being concatenated to OS level commands.
0
Attacker Value
Unknown

CVE-2024-50359

Disclosure Date: November 26, 2024 (last updated January 05, 2025)
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "scan_ap" API which are not properly sanitized before being concatenated to OS level commands.
0
Attacker Value
Unknown

CVE-2024-50358

Disclosure Date: November 26, 2024 (last updated January 05, 2025)
A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by authenticated users by restoring a tampered configuration backup.
0
Attacker Value
Unknown

CVE-2023-52335

Disclosure Date: November 22, 2024 (last updated January 13, 2025)
Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ConfigurationServlet servlet, which listens on TCP port 8080 by default. When parsing the column_value element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-17863.
Attacker Value
Unknown

CVE-2024-39364

Disclosure Date: September 27, 2024 (last updated September 28, 2024)
Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP request and are executed by the device automatically, without discrimination of origin or level of privileges of the user sending the commands.
0
Attacker Value
Unknown

CVE-2024-39275

Disclosure Date: September 27, 2024 (last updated October 08, 2024)
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user.
Attacker Value
Unknown

CVE-2024-38308

Disclosure Date: September 27, 2024 (last updated October 08, 2024)
Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.
Attacker Value
Unknown

CVE-2024-37187

Disclosure Date: September 27, 2024 (last updated October 08, 2024)
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
Attacker Value
Unknown

CVE-2024-34542

Disclosure Date: September 27, 2024 (last updated October 08, 2024)
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.