PT-2024-10216 · Aviatrix · Aviatrix Controller

Jakub Korepta

·

Published

2024-10-27

·

Updated

2026-01-15

·

CVE-2024-50603

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aviatrix Controller versions prior to 7.1.4191 and 7.2.x prior to 7.2.4996.
Description A critical command injection vulnerability in Aviatrix Controller allows unauthenticated attackers to execute arbitrary code due to the improper neutralization of special elements used in an OS command. This can be exploited by sending shell metacharacters to /v1/api in cloud type for list flightpath destination instances or src cloud type for flightpath connection test. Approximately 3% of enterprise cloud environments are affected, with attackers exploiting this vulnerability to deploy backdoors and crypto miners.
Recommendations To resolve the issue for each affected version, update to version 7.1.4191 or 7.2.4996 as soon as possible to prevent exploitation. As a temporary workaround, consider restricting access to the vulnerable API endpoints until a patch is applied. Additionally, monitor your environment for any signs of exploitation and apply mitigations to protect your organization from cyberattacks.

Exploit

Fix

LPE

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00546
CVE-2024-50603

Affected Products

Aviatrix Controller