PatchSiren cyber security CVE debrief
CVE-2024-28948 Advantech CVE debrief
Advantech ADAM-5630 devices running firmware versions prior to 2.5.2 contain a cross-site request forgery (CSRF) vulnerability. The flaw allows an attacker to induce authenticated users to perform unintended actions by circumventing same-origin policy protections. Successful exploitation could result in unauthorized configuration changes or operational disruption of affected industrial control system devices. CISA published advisory ICSA-24-270-02 on September 26, 2024, documenting this vulnerability with a CVSS 3.1 score of 8.0 (High). Advantech has released firmware version 2.5.2 to address this issue. Organizations should prioritize patching, especially for internet-accessible or critical infrastructure deployments.
- Vendor
- Advantech
- Product
- ADAM-5630
- CVSS
- HIGH 8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-26
- Original CVE updated
- 2024-09-26
- Advisory published
- 2024-09-26
- Advisory updated
- 2024-09-26
Who should care
Organizations operating Advantech ADAM-5630 devices in industrial automation, building management, or critical infrastructure environments. Priority attention for deployments with web management interfaces exposed to operational technology networks or where administrative access occurs from general-purpose workstations.
Technical summary
The Advantech ADAM-5630 is an industrial Ethernet-based data acquisition and control module. Versions prior to 2.5.2 fail to implement adequate CSRF protections in their web management interface. An attacker can craft malicious web content that, when loaded by an authenticated administrator, submits unauthorized requests to the device. The CVSS 3.1 attack vector (AV:A) indicates the attacker must be adjacent to the target network, though this includes any position where the attacker can deliver malicious content to the administrator's browser. The vulnerability scores High for confidentiality, integrity, and availability impacts, reflecting potential for complete device compromise.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade Advantech ADAM-5630 devices to firmware version 2.5.2 or later
- Implement network segmentation to restrict access to ADAM-5630 management interfaces
- Apply defense-in-depth strategies for industrial control systems per CISA guidance
- Review and validate CSRF protections in web-based device management interfaces
- Monitor for unauthorized configuration changes on affected devices
Evidence notes
CVE published and CISA advisory ICSA-24-270-02 released on 2024-09-26. CVSS 3.1 vector: AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Affected product: Advantech ADAM-5630 firmware versions prior to 2.5.2. Remediation: upgrade to version 2.5.2.
Official resources
-
CVE-2024-28948 CVE record
CVE.org
-
CVE-2024-28948 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-09-26