CVE-2024-50603 - Aviatrix Controllers OS Command Injection Vulnerability
Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
- Severity
- critical
- Product
- Aviatrix Controllers
- Published
- 2025-01-16
- EPSS
- 0.985
- CISA KEV
- Known exploited
- Ransomware
- Known campaign use
References and validation
- https://github.com/search?q=CVE-2024-50603&type=repositories
- https://nvd.nist.gov/vuln/detail/CVE-2024-50603
Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.