OS Command Injection Vulnerability Affects Advantech Devices
CVE-2024-50361
7.2HIGH
Summary
An OS Command Injection vulnerability has been identified in several Advantech EKI devices. This security flaw arises from improper sanitization of multiple parameters within the 'certificate_file_remove' API, allowing attackers to manipulate OS-level commands. Devices affected by this vulnerability include the EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO, particularly those running versions of firmware below the specified thresholds. This could facilitate unauthorized command execution, posing significant security risks to users and networks reliant on these systems.
Affected Version(s)
EKI-6333AC-1GPO 0
EKI-6333AC-2G 0
EKI-6333AC-2GD 0
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Diego Zaffaroni of Nozomi Networks found this bug during a security research activity.