CVE-2024-50603
Aviatrix Controllers OS Command Injection Vulnerability
- Published
- Jan 8, 2025
- Updated
- Oct 21, 2025
- Assigning CNA
- mitre
- Evidence observed
- Jan 16, 2025
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
Sources
2Nuclei template-based proof-of-concept for CVE-2024-50603, enabling automated detection and exploitation of the vulnerability in target environments.
- CVE-2024-50603Exploit
CVE-2024-50603: Aviatrix Controller Unauthenticated Command Injection
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.