Vulnerability Details CVE-2023-4203
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.6%
CVSS Severity
CVSS v3 Score 9.0
Products affected by CVE-2023-4203
-
cpe:2.3:h:advantech:eki-1521:-
-
cpe:2.3:h:advantech:eki-1522:-
-
cpe:2.3:h:advantech:eki-1524:-
-
cpe:2.3:o:advantech:eki-1521_firmware:-
-
cpe:2.3:o:advantech:eki-1521_firmware:1.08
-
cpe:2.3:o:advantech:eki-1521_firmware:1.09
-
cpe:2.3:o:advantech:eki-1521_firmware:1.15
-
cpe:2.3:o:advantech:eki-1521_firmware:1.21
-
cpe:2.3:o:advantech:eki-1521_firmware:1.24
-
cpe:2.3:o:advantech:eki-1522_firmware:-
-
cpe:2.3:o:advantech:eki-1522_firmware:1.08
-
cpe:2.3:o:advantech:eki-1522_firmware:1.09
-
cpe:2.3:o:advantech:eki-1522_firmware:1.15
-
cpe:2.3:o:advantech:eki-1522_firmware:1.21
-
cpe:2.3:o:advantech:eki-1522_firmware:1.24
-
cpe:2.3:o:advantech:eki-1524_firmware:-
-
cpe:2.3:o:advantech:eki-1524_firmware:1.08
-
cpe:2.3:o:advantech:eki-1524_firmware:1.09
-
cpe:2.3:o:advantech:eki-1524_firmware:1.15
-
cpe:2.3:o:advantech:eki-1524_firmware:1.21
-
cpe:2.3:o:advantech:eki-1524_firmware:1.24