Vulnerabilities
21 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-50603 | Unauthenticated OS Command Injection (RCE) in Aviatrix Controller CVE-2024-50603 is an unauthenticated OS command injection flaw (CWE-78) in Aviatrix Controllers, rated critical (CVSS 3.1: 9.8), that allows arbitrary code execution. It is triggered by sending shell metacharacters to the controller's /v1/api endpoint - in the cloud_type parameter for the list_flightpath_destination_instances action or the src_cloud_type parameter for the flightpath_connection_test action - where the input is not properly neutralized before being used in an OS command. An attacker who can reach the controller's API gains the ability to run arbitrary commands on the controller, and in observed attacks this has been used to install backdoors and cryptocurrency miners. Organizations running Aviatrix Controller versions before 7.1.4191, or 7.2.x versions before 7.2.4996, are affected. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-16 and carries a 98.5% EPSS probability of exploitation within 30 days. Do: Upgrade to Aviatrix Controller 7.1.4191 or later on the 7.1 branch, or 7.2.4996 or later on the 7.2 branch, per the vendor's instructions; if patching is not immediately possible, restrict network access to the controller's /v1/api endpoint or discontinue use as required by CISA's KEV action. Given active exploitation deploying backdoors and crypto miners, check controllers for signs of compromise (unexpected processes, persistence mechanisms, unusual outbound traffic) and rotate credentials accessible from the controller. | 9.8 | 99% | KEV PoC |
| moderatelikely thousands of controller deployments (estimate; enterprise-only install base, with low thousands of controllers observed internet-exposed in public scans) | |
| CVE-2022-38368 | An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2021-40870 | Unauthenticated File-Upload RCE via Path Traversal in Aviatrix Controller 6.x CVE-2021-40870 is an unrestricted file-upload flaw (CWE-23) in the Aviatrix Controller, affecting 6.x releases before 6.5-1804.1922, which scores a critical 9.8 because it requires no authentication, no user interaction, and is reachable over the network. An unauthenticated attacker sends a crafted upload request whose filename or path includes directory-traversal sequences and a dangerous file type, letting them write files outside the intended directory — including executable content — onto the controller host. Successful exploitation yields arbitrary code execution on the controller, the central management component of Aviatrix's cloud networking platform, which could give an attacker control of network orchestration and a foothold to pivot into connected cloud and on-premises environments. Any organization running an affected Aviatrix Controller version is at risk, with the highest exposure where the controller's management interface is reachable from the internet. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-01-18, public proof-of-concept code exists, and EPSS estimates a 93% probability of exploitation within 30 days. Do: Upgrade the Aviatrix Controller to 6.5-1804.1922 or later per the vendor's instructions, as required by CISA's KEV catalog. Until patched, restrict access to the controller's management interface (firewall/allow-list, VPN, or keep it off the public internet) and review the host for signs of compromise such as unexpected uploaded files, web shells, or unfamiliar processes, since ransomware use remains unknown. | 9.8 | 93% | KEV PoC ×2 |
| moderate≈ a few thousand internet-exposed Aviatrix Controllers (public scans in early 2022 showed thousands of exposed controller web interfaces) | |
| CVE-2021-31776 | Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfi Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2020-27569 | Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2020-27568 | Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. Note: All Aviatrix appliances are fully encrypted. This is an extra layer of security. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2020-26553 | An issue was discovered in Aviatrix Controller before R6.0.2483. An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2020-13417 | An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2020-7224 | The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2019-17387 +1 in the same advisory: …17388 | An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execu An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — |