CVE-2024-39364
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
27/09/2024
Last modified:
15/04/2026
Description
Advantech ADAM-5630 <br />
has built-in commands that can be executed without authenticating the <br />
user. These commands allow for restarting the operating system, <br />
rebooting the hardware, and stopping the execution. The commands can be <br />
sent to a simple HTTP request and are executed by the device <br />
automatically, without discrimination of origin or level of privileges <br />
of the user sending the commands.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
6.30
Severity 3.x
MEDIUM



