CVE-2024-50375

EUVD-2024-45073
A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
Affected Products (NVD)
VendorProductVersion
advantecheki-6333ac-2g_firmware
𝑥
< 1.6.5
advantecheki-6333ac-2gd_firmware
𝑥
< 1.6.5
advantecheki-6333ac-1gpo_firmware
𝑥
< 1.2.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
advantecheki-6333ac-2g_firmware
𝑥
≤ 1.6.3
ADP
advantecheki-6333ac-2gd_firmware
𝑥
≤ 1.6.3
ADP
advantecheki-6333ac-1gpo_firmware
𝑥
≤ 1.2.1
ADP