Advantech Update
2711Warning Date
Severity Level
Warning Number
Target Sector
24 February, 2021
● Critical
2021-2521
Energy - Water and Utilities - Manufacturing
Description:
Advantech has released a security update to address several vulnerabilities in the following products:
- BB-ESWGP506-2SFP-T
- Spectre RT Industrial Routers
Threats:
Attacker could exploit this vulnerability by doing the following:
- Sensitive information disclosure
- Execute arbitrary code
- Cross-site scripting (XSS)
- Man in the middle attack
Best practice and Recommendations:
The CERT team encourages users to review Advantech security advisory and apply the necessary updates:
- https://www.advantech-bb.cz/firmware
- Advantech no longer sells or maintains BB-ESWGP506-2SFP-T and considers it to be an end-of-life product.