CVE-2024-28948

Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:advantech:adam-5630_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:advantech:adam-5630:-:*:*:*:*:*:*:*

History

04 Oct 2024, 18:58

Type Values Removed Values Added
CPE cpe:2.3:o:advantech:adam-5630_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:advantech:adam-5630:-:*:*:*:*:*:*:*
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02 - Third Party Advisory, US Government Resource
First Time Advantech adam-5630
Advantech
Advantech adam-5630 Firmware
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

27 Sep 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-27 18:15

Updated : 2024-10-04 18:58


NVD link : CVE-2024-28948

Mitre link : CVE-2024-28948


JSON object : View

Products Affected

advantech

  • adam-5630
  • adam-5630_firmware
CWE
CWE-352

Cross-Site Request Forgery (CSRF)