CVE-2024-28948

Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:advantech:adam-5630_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:advantech:adam-5630:-:*:*:*:*:*:*:*

History

04 Oct 2024, 18:58

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-02 - Third Party Advisory, US Government Resource
CPE cpe:2.3:o:advantech:adam-5630_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:advantech:adam-5630:-:*:*:*:*:*:*:*
First Time Advantech adam-5630
Advantech
Advantech adam-5630 Firmware
CVSS v2 : unknown
v3 : 8.0
v2 : unknown
v3 : 8.8

30 Sep 2024, 12:45

Type Values Removed Values Added
Summary
  • (es) ADAM-5630 de Advantech contiene una vulnerabilidad de cross-site request forgery (CSRF). Permite a un atacante eludir parcialmente la misma política de origen, que está diseñada para evitar que distintos sitios web interfieran entre sí.

27 Sep 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-27 18:15

Updated : 2024-10-04 18:58


NVD link : CVE-2024-28948

Mitre link : CVE-2024-28948

CVE.ORG link : CVE-2024-28948


JSON object : View

Products Affected

advantech

  • adam-5630
  • adam-5630_firmware
CWE
CWE-352

Cross-Site Request Forgery (CSRF)