Unrated severityNVD Advisory· Published Nov 26, 2024· Updated Nov 26, 2024
CVE-2024-50367
CVE-2024-50367
Description
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands.
Affected products
4<= 1.6.3+ 3 more
- (no CPE)range: <= 1.6.3
- (no CPE)range: 0
- (no CPE)range: 0
- (no CPE)range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.