CVE-2024-50362: OS Command Injection
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "connectionprofileapply" API which are not properly sanitized before being concatenated to OS level commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50362?
CVE-2024-50362 is classified as a high severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2024-50362?
To fix CVE-2024-50362, upgrade the affected Advantech devices to a version greater than 1.6.3 for EKI-6333AC-2G and EKI-6333AC-2GD, or greater than 1.2.1 for EKI-6333AC-1GPO.
What devices are affected by CVE-2024-50362?
The affected devices are Advantech EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO, all running specific vulnerable versions.
What does CVE-2024-50362 exploit?
CVE-2024-50362 exploits improper neutralization of special elements in OS commands, leading to command injection vulnerabilities.
Is there a workaround for CVE-2024-50362?
Currently, the best approach to mitigate CVE-2024-50362 is to apply the recommended software updates as there are no effective workarounds.