U.S. CISA adds Aviatrix Controllers vulnerability to its Known Exploited Vulnerabilities catalog
ID: 5886eccb-30ab-5e5e-8b9a-21abc8270d0e
STIX ID: report--5886eccb-30ab-5e5e-8b9a-21abc8270d0e
Feed Name: Security Affairs
Threat Score
CISA added CVE-2024-50603 — a critical unauthenticated OS command-injection RCE in Aviatrix Controller (pre-7.1.4191 and 7.2.x pre-7.2.4996, fixed in 7.1.4191 and 7.2.4996) — to its Known Exploited Vulnerabilities catalog after public reports and a PoC showed active exploitation in the wild, with attackers deploying XMRig cryptominers and Sliver backdoors and CISA ordering federal remediation by February 6, 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
