CVE-2020-13416: CSRF
Published May 22, 2020
·Updated
An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets.
Affected Software
1 affected component
Aviatrix Controller<5.4.1066
Event History
May 22, 2020
CVE Published
via MITRE·08:48 PM
Data Sourced
via MITRE·08:48 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of the Aviatrix Controller vulnerability?
The vulnerability ID is CVE-2020-13416.
2
What is the severity level of CVE-2020-13416?
The severity level of CVE-2020-13416 is medium, with a severity value of 6.5.
3
What is the affected software of CVE-2020-13416?
The affected software is Aviatrix Controller versions up to and excluding 5.4.1066.
4
What is the CWE ID of CVE-2020-13416?
The CWE ID of CVE-2020-13416 is CWE-352.
5
How can the CSRF vulnerability on password resets be exploited?
The CSRF vulnerability on password resets can be exploited by performing unauthorized password resets through maliciously crafted requests.