EXPOSURES › CVE-2024-50603
CVE-2024-50603
HIGH ⌖ ON CISA KEV · EXPLOITEDAviatrix Controllers OS command injection allows unauthenticated attackers to execute arbitrary code via API endpoints.
This unpatched OS command injection vulnerability in Aviatrix Controllers enables remote code execution without authentication, posing a severe risk to DIB organizations relying on Aviatrix infrastructure. The vulnerability is actively exploited in the wild and linked to ransomware campaigns, making it a critical compliance failure for FedRAMP and NIST 800-171 vendors.
Shame score — Active exploitation of an unpatched RCE vulnerability in a critical network management product indicates severe negligence and exposes DIB organizations to immediate compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.