CVE-2024-50603 | Aviatrix Controller prior 7.1.4191/7.2.4996 /v1/api os command injection
A vulnerability, which was classified as very critical, was found in Aviatrix Controller. Affected is the function list_flightpath_destination_instances/flightpath_connection_test of the file /v1/api. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-50603. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.