CVE-2024-50371: OS Command Injection
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "wlanscan" operation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50371?
CVE-2024-50371 is classified as a medium severity vulnerability due to its potential to allow OS command injection.
How do I fix CVE-2024-50371?
To fix CVE-2024-50371, upgrade the affected devices to versions 1.6.4 or higher for EKI-6333AC-2G and EKI-6333AC-2GD, and 1.2.2 or higher for EKI-6333AC-1GPO.
What products are affected by CVE-2024-50371?
CVE-2024-50371 affects Advantech EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO devices running specified versions.
Could CVE-2024-50371 lead to data loss?
Yes, successful exploitation of CVE-2024-50371 could potentially lead to unauthorized access and data loss.
Is CVE-2024-50371 being actively exploited?
As of the latest information, there have been no confirmed reports of active exploitation of CVE-2024-50371.