Vulnerabilities (CVE)

Filtered by vendor Aviatrix Subscribe
Filtered by product Controller
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40870 1 Aviatrix 1 Controller 2023-08-08 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
CVE-2020-13417 4 Apple, Aviatrix, Linux and 1 more 6 Macos, Controller, Gateway and 3 more 2021-09-16 7.5 HIGH 9.8 CRITICAL
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.
CVE-2020-26553 1 Aviatrix 1 Controller 2020-11-23 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.