CVE-2024-50603: Aviatrix Controllers OS Command Injection Vulnerability
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloudtype for listflightpathdestinationinstances, or srccloudtype for flightpathconnectiontest.
Other sources
Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloudtype for listflightpathdestinationinstances, or srccloudtype for flightpathconnectiontest.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Aviatrix Controllerto a version that resolves this vulnerability.Fixed in 7.1.4191 - Upgrade
Upgrade
Aviatrix Controllerto a version that resolves this vulnerability.Fixed in 7.2.4996 - Compensating control
Discontinue use of Aviatrix Controller or apply vendor-provided mitigations if mitigations are unavailable; the vulnerability allows unauthenticated arbitrary code execution via shell metacharacters sent to /v1/api in cloud_type (list_flightpath_destination_instances) or src_cloud_type (flightpath_connection_test).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50603?
CVE-2024-50603 is classified as a critical vulnerability due to its potential for unauthorized remote code execution.
How do I fix CVE-2024-50603?
To fix CVE-2024-50603, upgrade Aviatrix Controller to version 7.1.4191 or later or 7.2.4996 or later.
Who is affected by CVE-2024-50603?
CVE-2024-50603 affects Aviatrix Controller versions prior to 7.1.4191 and 7.2.x prior to 7.2.4996.
What kind of attack is possible with CVE-2024-50603?
CVE-2024-50603 can allow an unauthenticated attacker to execute arbitrary commands on vulnerable systems.
What should I do if I cannot upgrade to mitigate CVE-2024-50603?
If you cannot upgrade, consider isolating affected systems and monitoring for unauthorized access until a patch is applied.