cbcvebase.
CVE-2024-50377
published 2024-11-26

CVE-2024-50377: A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD…

PriorityP426medium6.5CVSS 3.1
AVLACLPRHUIRSUCHIHAH
EPSS
0.19%
8.5th percentile
A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability is associated to the backup configuration functionality that by default encrypts the archives using a static password.

Affected

6 ranges
VendorProductVersion rangeFixed in
advantecheki-6333ac-1gpo<= <= 1.2.1
advantecheki-6333ac-1gpo_firmware< 1.2.21.2.2
advantecheki-6333ac-2g<= <= 1.6.3
advantecheki-6333ac-2g_firmware< 1.6.51.6.5
advantecheki-6333ac-2gd<= <= 1.6.3
advantecheki-6333ac-2gd_firmware< 1.6.51.6.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.