CVE-2024-50603
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 8, 2025
Updated: Jan 23, 2025
CWE ID 78
Summary
CVE-2024-50603 is a critical vulnerability affecting Aviatrix Controller versions before 7.1.4191 and 7.2.x before 7.2.4996. This issue stems from the lack of proper neutralization of special elements in OS commands. Consequently, an unauthenticated attacker can exploit this weakness by sending malicious input to the /v1/api endpoints, specifically in cloud_type for list_flightpath_destination_instances or src_cloud_type for flightpath_connection_test. The result is the execution of arbitrary code, posing a significant security risk to affected systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Aviatrix Controller
Affected Vendors
- Aviatrix Systems