Menu
Advantech industrial communication devices vulnerable to remote code execution

Advantech industrial communication devices vulnerable to remote code execution

Industrial equipment owners are advised to install the latest firmware updates to protect their Advantech Modbus gateway devices

Industrial computer manufacturer Advantech has fixed a critical vulnerability in a series of devices that handle data communication for industrial equipment with serial connections and TCP/IP networks.

The vulnerability was discovered by researchers from Core Security in the firmware of Advantech EKI-1200 series and ADAM-4572 devices, which are known as Modbus gateways.

The flaw is a buffer overflow in a CGI script and can be exploited remotely by attackers to execute arbitrary code on the device, the Core researchers said in an advisory published Monday.

Accessing the CGI script might require authentication in some cases, but attackers can use credentials for the root account that are hard coded in the firmware and are not always changed by users, the researchers said.

The Core advisory includes a proof-of-concept exploit that will trigger the buffer overflow on a vulnerable device using the hard-coded root password.

Advantech released a new version of the EKI-1200 firmware to address the issue. Users are advised to upgrade as soon as possible.


Follow Us

Join the newsletter!

Error: Please check your email address.

Tags patchesAdvantechCore Securitysecurityphysical securitypatch managementExploits / vulnerabilities

Featured

Slideshows

Meet the top performing HP partners in NZ

Meet the top performing HP partners in NZ

HP honoured leading partners across the channel at the Partner Awards 2017 in New Zealand, recognising excellence across the entire print and personal systems portfolio.

Meet the top performing HP partners in NZ
Tech industry comes together as Lexel celebrates turning 30

Tech industry comes together as Lexel celebrates turning 30

Leading figures within the technology industry across New Zealand came together to celebrate 30 years of success for Lexel Systems, at a milestone birthday occasion at St Matthews in the City.​

Tech industry comes together as Lexel celebrates turning 30
HP re-imagines education through Auckland event launch

HP re-imagines education through Auckland event launch

HP New Zealand held an inaugural Evolve Education event at Aotea Centre in Auckland, welcoming over 70 principals, teachers and education experts to explore ways of shaping and enhancing learning using technology.

HP re-imagines education through Auckland event launch
Show Comments