CVE-2024-50603
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
CISA KEV
- Vendor
- Aviatrix
- Product
- Controllers
- Due date
- 2025-02-06
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://docs.aviatrix.com/documentation/latest/release-notices/psirt-advisories/psirt-advisories.html?expand=true ; https://nvd.nist.gov/vuln/detail/CVE-2024-50603
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.