High severity7.5NVD Advisory· Published May 22, 2020· Updated Jun 17, 2026
CVE-2020-13415
CVE-2020-13415
Description
An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.
Affected products
3- Aviatrix/Controllerdescription
<=5.1+ 1 more
- (no CPE)range: <=5.1
- cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:*range: <=5.1
Patches
Vulnerability mechanics
References
1- docs.aviatrix.com/HowTos/security_bulletin_article.htmlnvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.