Junglewise Threat Intelligence

CVE-2024-50603: Aviatrix Controllers OS Command Injection Vulnerability

CVE-2024-50603 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2025-01-16

Executive brief

Aviatrix Controllers contain an OS command injection vulnerability in the /v1/api endpoint due to improper neutralization of shell metacharacters. An unauthenticated remote attacker can execute arbitrary code by sending malicious payloads in the cloud_type or src_cloud_type parameters.

Affected products

  • Aviatrix Controller before 7.1.4191, 7.2.x before 7.2.4996

Timeline

  • 2025-01-07: disclosed: Initial disclosure and NVD publication
  • 2025-01-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-01-16: exploited: Reported as exploited in the wild