CVE-2024-50361: OS Command Injection
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "certificatefileremove" API which are not properly sanitized before being concatenated to OS level commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50361?
CVE-2024-50361 is categorized as a high severity vulnerability due to its potential for OS command injection.
Which devices are affected by CVE-2024-50361?
The affected devices include Advantech EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO, with specific version limits.
How do I fix CVE-2024-50361?
To fix CVE-2024-50361, upgrade the affected devices to the latest firmware version provided by Advantech.
What type of vulnerability is CVE-2024-50361?
CVE-2024-50361 is classified as an OS Command Injection vulnerability, indicating improper neutralization of special elements.
What impact could CVE-2024-50361 have on my system?
Exploitation of CVE-2024-50361 could allow an attacker to execute arbitrary OS commands, leading to potential system compromise or data exfiltration.