OS Command Injection Vulnerability Affects Advantech Devices
CVE-2024-50361

7.2HIGH

Key Information:

Vendor
Advantech
Vendor
CVE Published:
26 November 2024

Summary

An OS Command Injection vulnerability has been identified in several Advantech EKI devices. This security flaw arises from improper sanitization of multiple parameters within the 'certificate_file_remove' API, allowing attackers to manipulate OS-level commands. Devices affected by this vulnerability include the EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO, particularly those running versions of firmware below the specified thresholds. This could facilitate unauthorized command execution, posing significant security risks to users and networks reliant on these systems.

Affected Version(s)

EKI-6333AC-1GPO 0

EKI-6333AC-2G 0

EKI-6333AC-2GD 0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Diego Zaffaroni of Nozomi Networks found this bug during a security research activity.
.