CRITICAL

CVE-2024-50603

Aviatrix Controller 2025-01-08 CVSS v3.1
CVSS
9.8
KEV

Description

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

Summary dbcve.org

OS command injection vulnerability in Aviatrix Controller allows unauthenticated attackers to execute arbitrary code via the /v1/api endpoint. The cloud_type parameter in list_flightpath_destination_instances and src_cloud_type in flightpath_connection_test APIs accept shell metacharacters without proper sanitization, enabling remote code execution.

Mitigation

Upgrade Aviatrix Controller to version 7.1.4191 or later (7.1.x) or 7.2.4996 or later (7.2.x). If immediate patching is not possible, restrict network access to the Controller management interface to prevent unauthenticated exploitation.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

98.55%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE