CVE-2024-50603
About
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
Rainforest analyst review
This is an OS command injection flaw in Aviatrix Controller. Certain API parameters, the cloud_type value for list_flightpath_destination_instances and src_cloud_type for flightpath_connection_test on the /v1/api endpoint, are passed into a shell command without neutralizing special characters. An unauthenticated attacker supplies shell metacharacters in those fields and executes arbitrary commands on the controller, with no login required.
Aviatrix Controller manages cloud networking across AWS, Azure, and GCP environments, so it holds cloud credentials and IAM roles and has the reach to touch the very infrastructure it orchestrates. Code execution on the controller therefore risks escalating into the connected cloud accounts, and post-disclosure reports described the flaw being used to drop cryptominers and backdoors, so exposed instances warrant investigation rather than a quiet patch. Upgrade to 7.1.4191 or 7.2.4996 or later, keep the controller off the public internet and limit its API to trusted management networks, and given the credentials it manages, rotate the cloud access keys and roles it uses and review cloud audit logs for unexpected activity originating from the controller.
References
- https://docs.aviatrix.com/documentation/latest/network-security/index.html
- https://docs.aviatrix.com/documentation/latest/release-notices/psirt-advisories/psirt-advisories.html?expand=true#remote-code-execution-vulnerability-in-aviatrix-controllers
- https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-50603
Related CVEs
Frequently asked questions
What is CVE-2024-50603?
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
How severe is CVE-2024-50603?
CVE-2024-50603 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2024-50603 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2024-50603?
Public advisories list the following as affected: controller. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2024-50603?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
