KEVIntel
10.0
CVSS
Critical

CVE-2024-50603

PUBLISHED

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements...

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
Aviatrix
Product
Controller
Published
Jan 08, 2025
EPSS

Description

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

cisa nuclei_scanner

CVSS scores

CVSS v3.1 10.0 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2025-01-16 00:00:00 UTC · Source

Proof of concept available

Recorded 2025-01-08 12:00:38 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 16, 2025

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

th3gokul/CVE-2024-50603

github · Created 2025-01-12 11:20:21 UTC · 16 stars

CVE-2024-50603: Aviatrix Controller Unauthenticated Command Injection

newlinesec/CVE-2024-50603

github · Created 2025-01-08 12:00:38 UTC · 6 stars

CVE-2024-50603-nuclei-poc

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • Detected by Nuclei