CVE-2024-50366: OS Command Injection
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "applicationsapply" API which are not properly sanitized before being concatenated to OS level commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50366?
CVE-2024-50366 is classified as a high-severity vulnerability due to the potential for OS command injection.
How do I fix CVE-2024-50366?
To remediate CVE-2024-50366, update the affected Advantech devices to their latest firmware versions.
Which devices are affected by CVE-2024-50366?
The devices affected by CVE-2024-50366 include the Advantech EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO.
What types of vulnerabilities are associated with CVE-2024-50366?
CVE-2024-50366 is associated with OS Command Injection, categorized under CWE-78.
When was CVE-2024-50366 disclosed?
CVE-2024-50366 was disclosed in 2024, highlighting significant security risks in specific Advantech products.