Back to overview

CVE-2024-50603

CRITICAL KEV CISA Exploitation: ACTIVE
10.0
CVSS 3.1
Description
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

Metadata

CVE ID
CVE-2024-50603
State
PUBLISHED
Assigner
mitre
Reserved
2024-10-27 00:00 UTC
Published
2025-01-08 00:00 UTC
Last updated
2025-10-21 22:55 UTC
Primary CWE
CWE-78
CWE-78 Improper Neutralization of Special Elements used in a…
Vendor / Product
Aviatrix / Controller
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Aviatrix Controllers OS Command Injection Vulnerability
Vendor
Aviatrix
Product
Controllers
Added to KEV
2025-01-16
Due date
2025-02-06
Ransomware
Not known
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA description
Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
Affected products (1)
VendorProductPlatformVersions
Aviatrix Controller 0 < 7.1.4191, 7.2.0 < 7.2.4996
Weakness (CWE)
CWESourceDescription
CWE-78 cna CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview