Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2020-26551
Disclosure Date: November 17, 2020 (last updated November 28, 2024)
An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.
0
Attacker Value
Unknown
CVE-2020-26553
Disclosure Date: November 17, 2020 (last updated November 28, 2024)
An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.
0
Attacker Value
Unknown
CVE-2020-26549
Disclosure Date: November 17, 2020 (last updated November 28, 2024)
An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.
0
Attacker Value
Unknown
CVE-2020-26550
Disclosure Date: November 17, 2020 (last updated November 28, 2024)
An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key.
0
Attacker Value
Unknown
CVE-2020-13415
Disclosure Date: May 22, 2020 (last updated November 27, 2024)
An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.
0
Attacker Value
Unknown
CVE-2020-13416
Disclosure Date: May 22, 2020 (last updated November 27, 2024)
An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets.
0
Attacker Value
Unknown
CVE-2020-13414
Disclosure Date: May 22, 2020 (last updated November 27, 2024)
An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.
0
Attacker Value
Unknown
CVE-2020-13413
Disclosure Date: May 22, 2020 (last updated November 27, 2024)
An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.
0
Attacker Value
Unknown
CVE-2020-13412
Disclosure Date: May 22, 2020 (last updated November 27, 2024)
An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, leading to CSRF.
0
Attacker Value
Unknown
CVE-2020-13417
Disclosure Date: May 22, 2020 (last updated November 27, 2024)
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.
0