CVE-2020-13417: Critical severity aviatrix controllers vulnerability
Published May 22, 2020
·Updated
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.
Affected Software
6 affected components
Aviatrix Controller<5.3
Aviatrix Gateway<5.3
Aviatrix VPN Client<2.10.7
Apple macOS
Linux Linux kernel
Microsoft Windows
Event History
May 22, 2020
CVE Published
via MITRE·08:47 PM
Data Sourced
via MITRE·08:47 PM
Description
Frequently Asked Questions
1
What is CVE-2020-13417?
CVE-2020-13417 is an Elevation of Privilege vulnerability discovered in Aviatrix VPN Client before 2.10.7.
2
How does CVE-2020-13417 affect Aviatrix VPN Client?
CVE-2020-13417 affects Aviatrix VPN Client installations before version 2.10.7.
3
Which operating systems are affected by CVE-2020-13417?
CVE-2020-13417 affects Linux, macOS, and Windows installations of Aviatrix VPN Client.
4
What is the severity level of CVE-2020-13417?
CVE-2020-13417 has a severity level of 9.8 (critical).
5
How can I fix CVE-2020-13417?
To fix CVE-2020-13417, update Aviatrix VPN Client to version 2.10.7 or later.