Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2023-2573 - CERT CVE
CVE-2023-2573
ID
CVE-2023-2573
Sažetak
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.
Reference
http://packetstormsecurity.com/files/172307/Advantech-EKI-15XX-Series-Command-Injection-Buffer-Overflow.html
http://seclists.org/fulldisclosure/2023/May/4
https://cyberdanube.com/en/multiple-vulnerabilities-in-advantech-eki-15xx-series/
https://www.advantech.com/en/support/details/firmware?id=1-1J9BEBL
https://www.advantech.com/en/support/details/firmware?id=1-1J9BECT
https://www.advantech.com/en/support/details/firmware?id=1-1J9BED3
http://packetstormsecurity.com/files/172307/Advantech-EKI-15XX-Series-Command-Injection-Buffer-Overflow.html
http://seclists.org/fulldisclosure/2023/May/4
https://cyberdanube.com/en/multiple-vulnerabilities-in-advantech-eki-15xx-series/
https://www.advantech.com/en/support/details/firmware?id=1-1J9BEBL
https://www.advantech.com/en/support/details/firmware?id=1-1J9BECT
https://www.advantech.com/en/support/details/firmware?id=1-1J9BED3
CVSS
Base:
8.8
Impact:
5.9
Exploitability:
2.8
Pristup
Vektor
Složenost
Autentikacija
NETWORK
LOW
LOW
Impact
Povjerljivost
Cjelovitost
Dostupnost
HIGH
HIGH
HIGH
CVSS vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Zadnje važnije ažuriranje
13-02-2025 - 17:16
Objavljeno
08-05-2023 - 13:15