Aviatrix Controller Security Update Advisory (CVE-2024-50603)

Overview

We have released a security update to address a vulnerability in Aviatrix Controller. Affected product users are advised to update to the latest version.

 

Affected Products

 

CVE-2024-50603

Aviatrix Controller Versions: ~ 7.1.4191 (excluded)
Aviatrix Controller Versions: 7.2.0 ~ 7.2.4996 (excluded)

 

Resolved Vulnerabilities

OS Command Injection Attack Vulnerability by Unauthorized Users (CVE-2024-50603)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

CVE-2024-50603

Aviatrix Controller Version: 7.1.4191
Aviatrix Controller Version: 7.2.4996

 

 

References

[1] PSIRT Advisories
https://docs.aviatrix.com/documentation/latest/release-notices/psirt-advisories/psirt-advisories.html?expand=true#remote-code-execution-vulnerability-in-aviatrix-controllers
[2] cve-2024-50603
https://www.cve.org/CVERecord?id=CVE-2024-50603