Authenticated Command Injection
Vulnerability Description
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-2573
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- S. Dietz (CyberDanube)
- T. Weber (CyberDanube)
References
- https://www.advantech.com/en/support/details/firmware?id=1-1J9BED3
- https://www.advantech.com/en/support/details/firmware?id=1-1J9BEBL
- https://www.advantech.com/en/support/details/firmware?id=1-1J9BECT
- https://cyberdanube.com/en/multiple-vulnerabilities-in-advantech-eki-15xx-series/
- http://seclists.org/fulldisclosure/2023/May/4
- http://packetstormsecurity.com/files/172307/Advantech-EKI-15XX-Series-Command-Injection-Buffer-Overflow.html
More from Advantech
View All →Affected Vendor
Advantech
View all reports →