CVE-2024-50374: OS Command Injection
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "capturepackages" operation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50374?
CVE-2024-50374 is classified as a critical vulnerability due to its potential for OS Command Injection.
Which devices are affected by CVE-2024-50374?
CVE-2024-50374 affects the Advantech devices EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO with specific versions.
How do I fix CVE-2024-50374?
To mitigate CVE-2024-50374, update the firmware on affected Advantech devices to versions greater than 1.6.3 for EKI-6333AC-2G and EKI-6333AC-2GD, and greater than 1.2.1 for EKI-6333AC-1GPO.
What is the potential impact of CVE-2024-50374?
Exploitation of CVE-2024-50374 could allow an attacker to execute arbitrary commands on the affected Advantech devices, leading to unauthorized access or control.
Is CVE-2024-50374 being actively exploited?
As of the latest information, there have been no confirmed reports of active exploitation of CVE-2024-50374, but it remains a critical vulnerability that should be addressed promptly.