CVE-2024-28948

Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:advantech:adam-5630_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:advantech:adam-5630:-:*:*:*:*:*:*:*

History

04 Oct 2024, 18:58

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02 - Third Party Advisory, US Government Resource
CPE cpe:2.3:h:advantech:adam-5630:-:*:*:*:*:*:*:*
cpe:2.3:o:advantech:adam-5630_firmware:*:*:*:*:*:*:*:*
First Time Advantech
Advantech adam-5630 Firmware
Advantech adam-5630
CVSS v2 : unknown
v3 : 8.0
v2 : unknown
v3 : 8.8

27 Sep 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-27 18:15

Updated : 2024-10-04 18:58


NVD link : CVE-2024-28948

Mitre link : CVE-2024-28948

CVE.ORG link : CVE-2024-28948


JSON object : View

Products Affected

advantech

  • adam-5630_firmware
  • adam-5630
CWE
CWE-352

Cross-Site Request Forgery (CSRF)