CVE-2023-4202

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:advantech:eki-1524_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1524:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:advantech:eki-1522_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1522:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:advantech:eki-1521_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1521:-:*:*:*:*:*:*:*

History

13 Feb 2025, 17:17

Type Values Removed Values Added
Summary (en) Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface. (en) Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.

21 Nov 2024, 08:34

Type Values Removed Values Added
Summary
  • (es) Los dispositivos Advantech EKI-1524, EKI-1522, EKI-1521 hasta la versión 1.21 están afectados por una vulnerabilidad de secuencias de comandos cruzadas almacenadas, que puede ser activada por usuarios autenticados en el campo del nombre del dispositivo de la interfaz web.
References () http://packetstormsecurity.com/files/174153/Advantech-EKI-1524-CE-EKI-1522-EKI-1521-Cross-Site-Scripting.html - () http://packetstormsecurity.com/files/174153/Advantech-EKI-1524-CE-EKI-1522-EKI-1521-Cross-Site-Scripting.html -
References () http://seclists.org/fulldisclosure/2023/Aug/13 - () http://seclists.org/fulldisclosure/2023/Aug/13 -
References () https://cyberdanube.com/en/en-st-polten-uas-multiple-vulnerabilities-in-advantech-eki-15xx-series/ - Exploit, Third Party Advisory () https://cyberdanube.com/en/en-st-polten-uas-multiple-vulnerabilities-in-advantech-eki-15xx-series/ - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 9.0

Information

Published : 2023-08-08 11:15

Updated : 2025-02-13 17:17


NVD link : CVE-2023-4202

Mitre link : CVE-2023-4202

CVE.ORG link : CVE-2023-4202


JSON object : View

Products Affected

advantech

  • eki-1522_firmware
  • eki-1521
  • eki-1521_firmware
  • eki-1524
  • eki-1524_firmware
  • eki-1522
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')