CVE-2023-2575
Authenticated Buffer Overflow
Vexday Risk Score
26Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 16.7%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
08 May 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/172307/Advantech-EKI-15XX-Series-Command-Injection-Buffer-Overflow.htmlhttps://cyberdanube.com/en/multiple-vulnerabilities-in-advantech-eki-15xx-series/http://seclists.org/fulldisclosure/2023/May/4https://www.advantech.com/en/support/details/firmware?id=1-1J9BEBLhttps://www.advantech.com/en/support/details/firmware?id=1-1J9BECThttps://www.advantech.com/en/support/details/firmware?id=1-1J9BED3