CVE-2024-39364

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
27/09/2024
Last modified:
15/04/2026

Description

Advantech ADAM-5630 <br /> has built-in commands that can be executed without authenticating the <br /> user. These commands allow for restarting the operating system, <br /> rebooting the hardware, and stopping the execution. The commands can be <br /> sent to a simple HTTP request and are executed by the device <br /> automatically, without discrimination of origin or level of privileges <br /> of the user sending the commands.

References to Advisories, Solutions, and Tools