CVE-2023-2573

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
08/05/2023
Last modified:
13/02/2025

Description

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:advantech:eki-1521_firmware:*:*:*:*:*:*:*:* 1.21 (including)
cpe:2.3:h:advantech:eki-1521:-:*:*:*:*:*:*:*
cpe:2.3:o:advantech:eki-1522_firmware:*:*:*:*:*:*:*:* 1.21 (including)
cpe:2.3:h:advantech:eki-1522:-:*:*:*:*:*:*:*
cpe:2.3:o:advantech:eki-1524_firmware:*:*:*:*:*:*:*:* 1.21 (including)
cpe:2.3:h:advantech:eki-1524:-:*:*:*:*:*:*:*