CVE-2024-50373: OS Command Injection
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "restoreconfigfromutility" operation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50373?
CVE-2024-50373 is classified as a high severity vulnerability due to the potential for OS command injection.
How do I fix CVE-2024-50373?
To address CVE-2024-50373, upgrade the affected Advantech devices to their latest firmware versions that mitigate the vulnerability.
Which devices are affected by CVE-2024-50373?
CVE-2024-50373 affects Advantech devices EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO, with specific firmware versions vulnerable.
What are the potential impacts of CVE-2024-50373?
Successful exploitation of CVE-2024-50373 could lead to unauthorized command execution on the affected devices.
Is there a workaround for CVE-2024-50373 if I cannot update immediately?
Currently, there are no documented workarounds for CVE-2024-50373, and updating to the latest firmware is recommended.