CVE-2019-17388: High severity aviatrix vpn client vulnerability
Published Dec 5, 2019
·Updated
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.
Affected Software
4 affected components
Aviatrix VPN Client<=2.2.10
FreeBSD FreeBSD
Linux Linux kernel
Microsoft Windows
Event History
Dec 5, 2019
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-17388.
2
What is the severity of CVE-2019-17388?
The severity of CVE-2019-17388 is high with a CVSS score of 7.8.
3
What is the affected software?
The Aviatrix VPN Client through version 2.2.10 on Windows and Linux is affected.
4
How can a local attacker exploit CVE-2019-17388?
A local attacker can exploit CVE-2019-17388 by gaining elevated privileges through file modifications in the Aviatrix VPN Client installation directory.
5
Is FreeBSD and Linux vulnerable to CVE-2019-17388?
No, FreeBSD and Linux are not vulnerable to CVE-2019-17388.