CVE-2024-50603

CVE Published 2025-01-08
Related CWE(s) CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Related Vendor(s) aviatrix
Related Product(s) controller
Exploitation Reported (CISA KEV) 2025-01-16
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References