First published: Fri May 22 2020(Updated: )
An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aviatrix Controllers | <5.4.1204 | |
Aviatrix VPN Client | =2.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13413 is a vulnerability discovered in Aviatrix Controller before version 5.4.1204 that allows for user enumeration via brute force.
CVE-2020-13413 has a severity rating of 5.3 (medium).
The affected software for CVE-2020-13413 includes Aviatrix Controller before version 5.4.1204 and Aviatrix VPN Client version 2.8.2.
To fix CVE-2020-13413, update Aviatrix Controller to version 5.4.1204 or later, and Aviatrix VPN Client to version 2.8.3 or later.
You can find more information about CVE-2020-13413 in the Aviatrix Controller security bulletin at https://docs.aviatrix.com/HowTos/security_bulletin_article.html#observable-response-discrepancy-from-api.