Aviatrix Controller Security Update Advisory (CVE-2024-50603)
Overview
We have released a security update to address a vulnerability in Aviatrix Controller. Affected product users are advised to update to the latest version.
Affected Products
CVE-2024-50603
Aviatrix Controller Versions: ~ 7.1.4191 (excluded)
Aviatrix Controller Versions: 7.2.0 ~ 7.2.4996 (excluded)
Resolved Vulnerabilities
OS Command Injection Attack Vulnerability by Unauthorized Users (CVE-2024-50603)
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-50603
Aviatrix Controller Version: 7.1.4191
Aviatrix Controller Version: 7.2.4996
References
[1] PSIRT Advisories
https://docs.aviatrix.com/documentation/latest/release-notices/psirt-advisories/psirt-advisories.html?expand=true#remote-code-execution-vulnerability-in-aviatrix-controllers
[2] cve-2024-50603
https://www.cve.org/CVERecord?id=CVE-2024-50603