CVE-2024-50603 – Remote Code Execution in Aviatrix Controller
A critical vulnerability, CVE-2024-50603, has been identified in Aviatrix Controller versions prior to 7.1.4191 and 7.2.x versions prior to 7.2.4996. This vulnerability stems from the improper neutralization of special elements used in OS commands, allowing an unauthenticated attacker to execute arbitrary code. Exploitation is possible by sending shell metacharacters to the /v1/api endpoint in the cloud_type parameter for list_flightpath_destination_instances or the src_cloud_type parameter for flightpath_connection_test. The IONIX research team developed and tested an exploit simulation on relevant assets to verify the vulnerability’s impact and assess potential exposure. The findings are detailed in this post
References: