the HTTP requests received are displayed to the user. The device doesn't
correctly neutralize malicious code when parsing HTTP requests to
generate page output.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37259 | Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output. |
Solution
ADAM-5550 is currently being phased out, and Advantech strongly recommends all ADAM-5550 users upgrade to ADAM-5630 firmware version 2.5.2 or higher.
Workaround
No workaround given by the vendor.
Mon, 07 Oct 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Advantech
Advantech adam-5550 Advantech adam 5550-firmware |
|
| CPEs | cpe:2.3:h:advantech:adam-5550:-:*:*:*:*:*:*:* cpe:2.3:o:advantech:adam_5550-firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Advantech
Advantech adam-5550 Advantech adam 5550-firmware |
Fri, 27 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Sep 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output. | |
| Title | Advantech ADAM-5550 Cross-site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-27T18:07:54.921Z
Reserved: 2024-06-26T15:09:26.536Z
Link: CVE-2024-38308
Updated: 2024-09-27T18:07:09.449Z
Status : Analyzed
Published: 2024-09-27T18:15:04.933
Modified: 2024-10-07T15:24:34.517
Link: CVE-2024-38308
No data.
OpenCVE Enrichment
No data.
EUVD