Gateway
by Aviatrix
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-13417 | Cri | 0.64 | 9.8 | 0.02 | May 22, 2020 | An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters. | ||
| CVE-2022-38368 | Hig | 0.57 | 8.8 | 0.01 | Aug 15, 2022 | An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands. | ||
| CVE-2020-13414 | Hig | 0.49 | 7.5 | 0.01 | May 22, 2020 | An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software. |
- risk 0.64cvss 9.8epss 0.02
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.