Advantech EKI-6333AC-2G Vulnerable to OS Command Injection
CVE-2024-50359
7.2HIGH
Summary
A vulnerability related to improper neutralization of special elements used in OS commands has been identified in multiple Advantech EKI series devices. This flaw occurs due to inadequate sanitization of parameters associated with the 'scan_ap' API, enabling unauthorized OS command execution. The affected devices, including EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO, may be at risk of exploitation if not properly secured. It is critical for users of these devices to review their security measures and apply necessary updates to mitigate potential risks.
Affected Version(s)
EKI-6333AC-1GPO 0
EKI-6333AC-2G 0
EKI-6333AC-2GD 0
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Diego Zaffaroni of Nozomi Networks found this bug during a security research activity.