Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Controller CRITICAL 9.8
CVE-2024-50603 KEVEPSS 99%

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used…

Fix: 7.1.4191 / 7.2.4996+
Fix from $2,300 2025-01-08
Gateway HIGH 8.8
CVE-2022-38368

An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an aut…

Fix: 6.6.5712 / 6.7.1376+
Fix from $1,950 2022-08-15
Controller CRITICAL 9.8
CVE-2021-40870 KEVEPSS 93%

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allow…

Fix: 6.2.2043 / 6.3.2490+
Fix from $2,300 2021-09-13
Vpn Client HIGH 7.8
CVE-2021-31776

Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine …

Fix: 2.14.14+
Fix from $1,950 2021-04-29
Controller HIGH 7.5
CVE-2020-27568

Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. …

Mitigation only
Fix from $1,950 2021-04-21
Openvpn HIGH 7.5
CVE-2020-27569

Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be lev…

Fix: after 2.8.2
Fix from $1,950 2021-04-21
Controller CRITICAL 9.8
CVE-2020-26553

An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web …

No fix yet
Fix from $2,300 2020-11-17
Controller HIGH 8.8
CVE-2020-26548

An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any u…

No fix yet
Fix from $1,950 2020-11-17
Controller HIGH 7.5
CVE-2020-26549

An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed…

No fix yet
Fix from $1,950 2020-11-17
Controller HIGH 7.5
CVE-2020-26550

An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a thre…

No fix yet
Fix from $1,950 2020-11-17
Controller HIGH 7.5
CVE-2020-26551

An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.

No fix yet
Fix from $1,950 2020-11-17
Controller HIGH 7.5
CVE-2020-26552

An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints, do not require a valid sess…

No fix yet
Fix from $1,950 2020-11-17
Controller CRITICAL 9.8
CVE-2020-13417

An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Lin…

Fix: 2.10.7 / 5.3+
Fix from $2,300 2020-05-22
Controller HIGH 8.8
CVE-2020-13412

An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, lead…

Fix: 5.4.1204+
Fix from $1,950 2020-05-22
Controller HIGH 7.5
CVE-2020-13414

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

Fix: 5.4.1204+
Fix from $1,950 2020-05-22
Controller HIGH 7.5
CVE-2020-13415

An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a con…

Fix: after 5.1
Fix from $1,950 2020-05-22
Controller MEDIUM 6.5
CVE-2020-13416

An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, wh…

Fix: 5.4.1066+
Fix from $1,600 2020-05-22
Controller MEDIUM 5.3
CVE-2020-13413

An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to per…

Fix: 5.4.1204+
Fix from $1,600 2020-05-22
Openvpn CRITICAL 9.8
CVE-2020-7224

The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; t…

Fix: after 2.5.7
Fix from $2,300 2020-04-16
Vpn Client HIGH 7.8
CVE-2019-17387

An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary…

Fix: after 2.2.10
Fix from $1,950 2019-12-05
Vpn Client HIGH 7.8
CVE-2019-17388

Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute…

Fix: after 2.2.10
Fix from $1,950 2019-12-05