Advantech EKI-6333AC-2G Vulnerable to OS Command Injection
CVE-2024-50359

7.2HIGH

Key Information:

Vendor
Advantech
Vendor
CVE Published:
26 November 2024

Summary

A vulnerability related to improper neutralization of special elements used in OS commands has been identified in multiple Advantech EKI series devices. This flaw occurs due to inadequate sanitization of parameters associated with the 'scan_ap' API, enabling unauthorized OS command execution. The affected devices, including EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO, may be at risk of exploitation if not properly secured. It is critical for users of these devices to review their security measures and apply necessary updates to mitigate potential risks.

Affected Version(s)

EKI-6333AC-1GPO 0

EKI-6333AC-2G 0

EKI-6333AC-2GD 0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Diego Zaffaroni of Nozomi Networks found this bug during a security research activity.
.