logo

U.S. CISA adds Aviatrix Controllers vulnerability to its Known Exploited Vulnerabilities catalog

ID: 5886eccb-30ab-5e5e-8b9a-21abc8270d0e

STIX ID: report--5886eccb-30ab-5e5e-8b9a-21abc8270d0e

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2025-01-17

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added CVE-2024-50603 — a critical unauthenticated OS command-injection RCE in Aviatrix Controller (pre-7.1.4191 and 7.2.x pre-7.2.4996, fixed in 7.1.4191 and 7.2.4996) — to its Known Exploited Vulnerabilities catalog after public reports and a PoC showed active exploitation in the wild, with attackers deploying XMRig cryptominers and Sliver backdoors and CISA ordering federal remediation by February 6, 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.