HIGH · 8.0

CVE-2024-28948

Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from...

Vulnerability Description

Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.

CVSS Score

8.0

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AdvantechAdam-5630 Firmware< 2.5.2
AdvantechAdam-5630-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-28948?

CVE-2024-28948 is a vulnerability with a CVSS score of 8.0 (HIGH). Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from...

How severe is CVE-2024-28948?

CVE-2024-28948 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-28948?

Check the references section above for vendor advisories and patch information. Affected products include: Advantech Adam-5630 Firmware, Advantech Adam-5630.