CVE-2024-50369: OS Command Injection
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "multiplessidhtm" API which are not properly sanitized before being concatenated to OS level commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50369?
CVE-2024-50369 is classified as a high severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2024-50369?
To mitigate CVE-2024-50369, upgrade the affected Advantech devices to the latest firmware versions.
Which devices are affected by CVE-2024-50369?
CVE-2024-50369 affects Advantech EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO models with specific version limitations.
What type of vulnerability is CVE-2024-50369?
CVE-2024-50369 is categorized as an OS command injection vulnerability under CWE-78.
What are the risks associated with CVE-2024-50369?
Exploitation of CVE-2024-50369 could allow attackers to execute arbitrary OS commands, potentially compromising system integrity.