PT-2024-9474 · Advantech · Advantech Eki-6333Ac-1Gpo+1
Diego Zaffaroni
·
Published
2024-11-26
·
Updated
2024-11-29
·
CVE-2024-50370
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Advantech EKI-6333AC-2G versions 1.6.3 and earlier
Advantech EKI-6333AC-2GD versions 1.6.3 and earlier
Advantech EKI-6333AC-1GPO versions 1.2.1 and earlier
Description:
The issue exists due to the lack of neutralization of special elements used in an operating system command. This can be exploited by a remote attacker to execute arbitrary commands with root privileges. The vulnerability affects the
edgserver service, which is enabled by default on the access point. No authentication is required to exploit this issue, and malicious commands are executed with root privileges. The source of the vulnerability resides in the processing code associated with the cfg cmd set eth conf operation.Recommendations:
For Advantech EKI-6333AC-2G versions 1.6.3 and earlier, update to a version later than 1.6.3.
For Advantech EKI-6333AC-2GD versions 1.6.3 and earlier, update to a version later than 1.6.3.
For Advantech EKI-6333AC-1GPO versions 1.2.1 and earlier, update to a version later than 1.2.1.
As a temporary workaround, consider disabling the
edgserver service until a patch is available.
Restrict access to the cfg cmd set eth conf operation to minimize the risk of exploitation.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advantech Eki-6333Ac-1Gpo
Advantech Eki-6333Ac-2G