CVE-2024-50375: OS Command Injection
A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50375?
CVE-2024-50375 is classified as a critical vulnerability due to missing authentication for critical functions.
How do I fix CVE-2024-50375?
To mitigate CVE-2024-50375, upgrade the affected Advantech devices to the latest firmware versions: EKI-6333AC-2G and EKI-6333AC-2GD to greater than 1.6.3, and EKI-6333AC-1GPO to greater than 1.2.1.
Which devices are affected by CVE-2024-50375?
The devices affected by CVE-2024-50375 are Advantech EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO manufactured with specific firmware versions.
Can CVE-2024-50375 be exploited remotely?
Yes, CVE-2024-50375 can be exploited by remote unauthenticated users, potentially leading to unauthorized access.
What is the impact of exploiting CVE-2024-50375?
Exploitation of CVE-2024-50375 can allow attackers to access critical functionalities of the affected devices without proper authentication.