CVE Feed

    Dashboard / CVE / CVE-2024-50603

    CVE-2024-50603

    An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

    Published:Jan 8, 2025
    Last Modified:Nov 5, 2025
    EPS:Jan 8, 2025
    EPSS Score:0.94352
    CVSS Score:10

    CISA Notification

    Description

    An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

    Required Action:

    Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Feb 6, 2025
    582 days ago
    Alert Date
    Jan 16, 2025
    603 days ago

    Affected Products

    Vendor
    Aviatrix
    Product
    Controller

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High