CVE-2024-50365: OS Command Injection
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "lanapply" API which are not properly sanitized before being concatenated to OS level commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50365?
CVE-2024-50365 is classified as a high-severity vulnerability due to OS command injection risks.
How do I fix CVE-2024-50365?
To mitigate CVE-2024-50365, update the affected devices to the latest versions specified by the manufacturer.
Which devices are affected by CVE-2024-50365?
The affected devices include Advantech EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO with their respective maximum versions.
What is the nature of the vulnerability in CVE-2024-50365?
CVE-2024-50365 involves improper neutralization of special elements that can lead to OS command injection.
How can I determine if my device is vulnerable to CVE-2024-50365?
Check the firmware version of your Advantech devices against the vulnerable versions listed in CVE-2024-50365.