VYPR
Unrated severityNVD Advisory· Published Nov 26, 2024· Updated Nov 26, 2024

CVE-2024-50366

CVE-2024-50366

Description

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "applications_apply" API which are not properly sanitized before being concatenated to OS level commands.

Affected products

4
  • Advantech/EKI-6333AC-2Gllm-fuzzy4 versions
    <=1.6.3+ 3 more
    • (no CPE)range: <=1.6.3
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.