Aviatrix Controller versions before 7.1.4191 and 7.2.x before 7.2.4996 are vulnerable to command injection due to improper neutralization of special elements in OS commands. An unauthenticated attacker can exploit this by sending shell metacharacters to the /v1/api endpoint in the cloud_type parameter for list_flightpath_destination_instances or the src_cloud_type parameter for flightpath_connection_test, resulting in arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-50603, a critical unauthenticated OS command injection vulnerability in Aviatrix Controller (versions prior to 7.1.4191 and 7.2.x before 7.2.4996). The exploit is implemented in a single Python script (poc.py) and is accompanied by a detailed README.md that explains the vulnerability, its impact, and usage instructions. The PoC works by sending a specially crafted POST request to the /v1/backend API endpoint of the target Aviatrix Controller. The 'cloud_type' parameter is injected with a payload such as '1|$(sleep 5)', exploiting improper input sanitization in the backend PHP code. By default, the script uses a time-based 'sleep' command to detect successful exploitation (blind command injection), but it also allows the user to specify arbitrary commands, including OOB payloads for exfiltration. The script supports scanning a single target or multiple targets in parallel, and provides clear output on vulnerability status. No authentication is required to exploit the vulnerability. The exploit is a true PoC: it demonstrates code execution but does not include weaponized or post-exploitation features. The only fingerprintable endpoint is the /v1/backend API path on the target controller, which must be accessible over HTTP(S).
This repository contains a Python-based exploitation tool (cvehunter.py) for CVE-2024-50603, an unauthenticated command injection vulnerability in the Aviatrix Controller. The tool is designed to automate both detection and exploitation of the vulnerability. It supports targeting single URLs or lists of URLs, uses asynchronous requests for performance, and integrates with an external SSRF callback service (cvssadvisor.com) to verify successful exploitation. The main script, cvehunter.py, is the entry point and provides command-line options for specifying targets, threading, proxy usage, verbosity, and output file. The tool is operational, providing real exploitation capabilities, and is intended for use by security professionals for testing and validation of the vulnerability. The README provides usage instructions, references, and credits. No hardcoded exploit payloads are present, as the tool dynamically crafts requests based on user input and the SSRF callback mechanism.
This repository contains a Nuclei proof-of-concept (POC) exploit for CVE-2024-50603, a critical unauthenticated remote code execution vulnerability in Aviatrix Controller (prior to 7.1.4191 and 7.2.x before 7.2.4996). The main file, 'CVE-2024-50603.yaml', is a Nuclei template that sends a crafted POST request to the /v1/api endpoint of the target, injecting a shell command via the 'cloud_type' parameter. The injected command uses curl to send the contents of /etc/passwd to an attacker-controlled endpoint (specified by the 'oast' variable, typically an interactsh-url). The template checks for successful exploitation by matching HTTP status 200 and the presence of 'root:.*:0:0:' in the exfiltrated data. The repository is structured as a simple POC with a single YAML template and a brief README. No fake or destructive code is present; the exploit is focused on demonstrating the vulnerability and exfiltration capability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.