TROYANOSYVIRUS
Retour aux CVEs

CVE-2024-50603

CRITICALCISA KEV
10.0

Description

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

Details CVE

Score CVSS v3.110.0
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie1/8/2025
Derniere modification11/5/2025
Sourcekev
Observations honeypot0

CISA KEV

FournisseurAviatrix
ProduitControllers
Nom vulnerabiliteAviatrix Controllers OS Command Injection Vulnerability
Date ajout KEV2025-01-16
Date limite remediation2025-02-06
Utilise dans ransomwareUnknown

Produits affectes

aviatrix:controller

Faiblesses (CWE)

CWE-78CWE-78

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.