CVE-2024-38308

Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:advantech:adam_5550-firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:adam-5550:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-27 18:15

Updated : 2024-10-07 15:24


NVD link : CVE-2024-38308

Mitre link : CVE-2024-38308

CVE.ORG link : CVE-2024-38308


JSON object : View

Products Affected

advantech

  • adam-5550
  • adam_5550-firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')