PT-2024-27936 · Advantech · Advantech Adam 5550

Aarón Flecha Menéndez

+1

·

Published

2024-09-26

·

Updated

2024-10-07

·

CVE-2024-38308

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech ADAM 5550 (affected versions not specified)
Description The device's web application includes a "logs" page where all HTTP requests received are displayed to the user. However, it fails to correctly neutralize malicious code when parsing HTTP requests to generate page output, potentially exposing users to code injection attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-03102
CVE-2024-38308

Affected Products

Advantech Adam 5550