Aviatrix

Controller

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.43%
  • Veröffentlicht 17.11.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:20:03

An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any user on the system.

  • EPSS 0.13%
  • Veröffentlicht 22.05.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:12

An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, leading to CSRF.

Exploit
  • EPSS 1.17%
  • Veröffentlicht 22.05.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:12

An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.

  • EPSS 0.19%
  • Veröffentlicht 22.05.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:12

An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 22.05.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:12

An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Av...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 22.05.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:12

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 22.05.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:12

An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.