CVE-2024-50363: OS Command Injection
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "mpapply" API which are not properly sanitized before being concatenated to OS level commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50363?
CVE-2024-50363 is categorized as a high-severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2024-50363?
To fix CVE-2024-50363, upgrade the affected Advantech devices to the latest firmware versions available.
Which devices are affected by CVE-2024-50363?
CVE-2024-50363 impacts Advantech devices EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO with specific firmware versions.
What type of vulnerability is CVE-2024-50363 classified as?
CVE-2024-50363 is classified as an OS Command Injection vulnerability, representing improper neutralization of special elements.
Can CVE-2024-50363 lead to remote code execution?
Yes, CVE-2024-50363 could potentially allow an attacker to execute arbitrary commands on the affected devices.