CVE-2024-39364
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 306
Summary
CVE-2024-39364 is a vulnerability affecting the Advantech ADAM-5630 device. The issue resides in the built-in commands of the device, which can be triggered without user authentication. These commands carry significant power, enabling the restarting of the operating system, rebooting of hardware, and halting of execution. The vulnerability is notable because the commands can be activated through a simple HTTP request, making no distinction based on the sender's privileges or origin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.