{"Remotely Exploitable OS Command Injection Vulnerability Affects Advantech Devices"}
CVE-2024-50372
What is CVE-2024-50372?
An OS Command Injection vulnerability exists in specific Advantech EKI series devices that allows remote unauthenticated users to execute malicious commands with root privileges. This security flaw affects devices running certain versions, specifically EKI-6333AC-2G (up to 1.6.3), EKI-6333AC-2GD (up to 1.6.3), and EKI-6333AC-1GPO (up to 1.2.1). The vulnerability arises from improper handling of elements used in OS command execution and is linked to the 'backup_config_to_utility' function within the default 'edgserver' service. As the service is accessible without authentication, attackers can exploit this weakness to gain control over the device.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EKI-6333AC-1GPO 0
EKI-6333AC-2G 0
EKI-6333AC-2GD 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
