CVE-2024-50377: OS Command Injection
A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability is associated to the backup configuration functionality that by default encrypts the archives using a static password.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50377?
CVE-2024-50377 is classified as a high severity vulnerability due to the use of hard-coded credentials.
How do I fix CVE-2024-50377?
To mitigate CVE-2024-50377, upgrade affected devices to the latest firmware version that removes hard-coded credentials.
Which devices are affected by CVE-2024-50377?
CVE-2024-50377 affects Advantech devices including EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO with specific versions.
What impact does CVE-2024-50377 have on device security?
CVE-2024-50377 can lead to unauthorized access and control of devices due to the presence of hard-coded credentials.
Is there a workaround for CVE-2024-50377?
While permanent fixes are preferred, temporarily changing administrative access protocols may help mitigate risks from CVE-2024-50377 until updates are applied.