CVE-2023-4202

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
08/08/2023
Last modified:
13/02/2025

Description

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:advantech:eki-1524_firmware:*:*:*:*:*:*:*:* 1.21 (including)
cpe:2.3:h:advantech:eki-1524:-:*:*:*:*:*:*:*
cpe:2.3:o:advantech:eki-1522_firmware:*:*:*:*:*:*:*:* 1.21 (including)
cpe:2.3:h:advantech:eki-1522:-:*:*:*:*:*:*:*
cpe:2.3:o:advantech:eki-1521_firmware:*:*:*:*:*:*:*:* 1.21 (including)
cpe:2.3:h:advantech:eki-1521:-:*:*:*:*:*:*:*