7.5
CVE-2020-26549
- EPSS 0.61%
- Veröffentlicht 17.11.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:20:03
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aviatrix ≫ Controller Version5.3.1516
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.61% | 0.673 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.