CVE-2024-50370: OS Command Injection
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "cfgcmdsetethconf" operation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50370?
CVE-2024-50370 has a severity level that can be categorized as critical due to its potential for OS command injection.
How do I fix CVE-2024-50370?
To fix CVE-2024-50370, update the affected devices to their respective patched versions: EKI-6333AC-2G and EKI-6333AC-2GD to versions greater than 1.6.3, and EKI-6333AC-1GPO to a version greater than 1.2.1.
What devices are affected by CVE-2024-50370?
CVE-2024-50370 affects Advantech EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO, specifically those running the specified versions or earlier.
What type of vulnerability is CVE-2024-50370?
CVE-2024-50370 represents an OS Command Injection vulnerability, classified under CWE-78 for improper neutralization of special elements.
What can happen if CVE-2024-50370 is exploited?
If exploited, CVE-2024-50370 can allow an attacker to execute arbitrary commands on the affected devices, potentially leading to unauthorized access and control.