Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.
History

Thu, 13 Feb 2025 17:00:00 +0000

Type Values Removed Values Added
Description Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request. Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.

Wed, 29 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2025-02-13T16:44:36.399Z

Reserved: 2023-05-08T11:13:35.330Z

Link: CVE-2023-2574

cve-icon Vulnrichment

Updated: 2024-08-02T06:26:09.703Z

cve-icon NVD

Status : Modified

Published: 2023-05-08T13:15:09.790

Modified: 2025-02-13T17:16:21.543

Link: CVE-2023-2574

cve-icon Redhat

No data.