Authenticated Command Injection
CVE-2023-2573
8.8HIGH
What is CVE-2023-2573?
The command injection vulnerability in Advantech EKI-1524, EKI-1522, and EKI-1521 devices allows authenticated users to exploit the NTP server input field. By sending a specially crafted POST request, attackers can potentially execute arbitrary commands on the affected devices, risking the integrity and confidentiality of the network. Users should update to the latest firmware versions to mitigate this risk.
Affected Version(s)
EKI-1521 0 <= 1.21
EKI-1522 0 <= 1.21
EKI-1524 0 <= 1.21
