CVE-2024-50376: OS Command Injection
A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited remotely leveraging a rogue Wi-Fi access point with a malicious SSID.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50376?
CVE-2024-50376 has been classified as a moderate to high severity vulnerability due to its potential for remote exploitation through cross-site scripting.
How do I fix CVE-2024-50376?
To fix CVE-2024-50376, update the affected Advantech devices to the latest firmware versions that address this vulnerability.
What products are affected by CVE-2024-50376?
The products affected by CVE-2024-50376 include Advantech EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO with specific firmware versions.
Can CVE-2024-50376 be exploited remotely?
Yes, CVE-2024-50376 can be exploited remotely, allowing attackers to execute malicious scripts on vulnerable devices.
What type of vulnerability is CVE-2024-50376?
CVE-2024-50376 is categorized as a Cross-site Scripting (XSS) vulnerability due to improper neutralization of user input.