Vulnerability in Advantech Bedrock Web Interface Allowing Unauthorized Commands

CVE-2024-39364
Currently unrated 🤨

Key Information

Vendor
Advantech
Vendor
CVE Published:
27 September 2024

Summary

Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP request and are executed by the device automatically, without discrimination of origin or level of privileges of the user sending the commands.

Timeline

  • Vulnerability published.

Collectors

NVD Database
.