Threat Advisory

Command Injection Exploitation in Aviatrix Controllers

Threat: Vulnerability/Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

 

EXECUTIVE SUMMARY[/subscribe_to_unlock_form]

 

EXECUTIVE SUMMARY[emaillocker id="1283"]

 The identification of a critical vulnerability in the Aviatrix Controller has exposed numerous cloud environments to unauthorized access and exploitation. This vulnerability, categorized as CVE-2024-50603, is a Remote Code Execution (RCE) flaw that allows unauthenticated attackers to remotely execute commands on the Aviatrix Controller. The flaw arises from improper neutralization of user-supplied inputs within specific API endpoints. Exploitation of this vulnerability poses significant risks, especially in cloud environments where the Aviatrix Controller is integrated with administrative control planes. Attackers leveraging this flaw have been observed deploying cryptojacking malware and back doors, emphasizing the need for immediate action by affected entities.

The vulnerability arises from improper handling of user-supplied input in the Aviatrix Controller's API, specifically in the API endpoints list_flightpath_destination_instances and flightpath_connection_test. These endpoints fail to sanitize parameters like cloud_type and src_cloud_type, allowing attackers to inject malicious OS commands that can be executed on the server. The flaw enables attackers to gain control over the system with no authentication, posing a high-risk threat, particularly in cloud environments. Aviatrix Controller, by default, is granted high IAM privileges in AWS, providing a potential for privilege escalation, which increases the scope of impact once the system is compromised.

Successful exploitation of this vulnerability has already been observed in the wild, primarily targeting publicly exposed instances of Aviatrix Controller. Threat actors have used this vector to deploy cryptocurrency mining tools and backdoors, suggesting an intent to maintain long-term access and monetization capabilities. The design of the Aviatrix Controller, with its high-privilege roles in cloud environments, further amplifies the risks by potentially allowing attackers to move laterally into broader cloud infrastructure. While technical defenses and mitigations are paramount, the swift patching of vulnerable systems and proactive monitoring for compromise are critical steps for limiting the threat’s scope and impact.

THREAT PROFILE:

Tactic Technique ID Technique
Initial Access T1190 Exploit Public-Facing Application
Execution T1059 Command and Scripting Interpreter
Persistence T1505 Server Software Component
Defense Evasion T1078 Valid Accounts
Discovery T1083 File and Directory Discovery
Impact T1496 Resource Hijacking

REFERENCES:

The following reports contain further technical details:
https://www.darkreading.com/cloud-security/cloud-attackers-exploit-max-critical-aviatrix-rce-flaw

[/emaillocker]
crossmenu