PT-2024-9482 · Advantech · Advantech Eki-6333Ac-1Gpo+1
Diego Zaffaroni
·
Published
2024-07-05
·
Updated
2024-11-26
·
CVE-2024-50358
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Advantech EKI-6333AC-2G versions 1.6.3 and earlier
Advantech EKI-6333AC-2GD versions 1.6.3 and earlier
Advantech EKI-6333AC-1GPO versions 1.2.1 and earlier
Description:
A security issue was discovered in Advantech devices, related to the restoration of a tampered configuration backup. This can be exploited by authenticated users, potentially allowing a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations:
For Advantech EKI-6333AC-2G versions 1.6.3 and earlier, update to a version later than 1.6.3 to resolve the issue.
For Advantech EKI-6333AC-2GD versions 1.6.3 and earlier, update to a version later than 1.6.3 to resolve the issue.
For Advantech EKI-6333AC-1GPO versions 1.2.1 and earlier, update to a version later than 1.2.1 to resolve the issue.
As a temporary workaround, consider restricting access to the configuration backup restoration feature until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advantech Eki-6333Ac-1Gpo
Advantech Eki-6333Ac-2G