CVE-2024-50603 is a critical remote code execution (RCE) vulnerability affecting Aviatrix Controller versions before 7.1.4191 and 7.2.x before 7.2.4996. It stems from improper neutralization of special characters in OS commands, allowing unauthenticated attackers to execute arbitrary code by injecting shell metacharacters into specific API endpoints. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Its high EPSS and FAUCET Risk Score further emphasize its significant threat. CVE-2024-50603 is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog and extensive media coverage. While no Metasploit or ExploitDB modules are publicly available, Nuclei templates exist, and there is significant community discussion surrounding its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.1.4191CPE matchmatch criteria | cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* | ||
>= 7.2, < 7.2.4996CPE matchmatch criteria | cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* | ||
>= 0, < 7.1.4191CPE match | cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* | ||
>= 7.2.0, < 7.2.4996CPE match | cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.