Security Advisory

CVE-2024-39364

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-09-27 17:48:22
Last updated 2024-09-27 18:13:38
Assigner icscert
State PUBLISHED

Description

Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP request and are executed by the device automatically, without discrimination of origin or level of privileges of the user sending the commands.