CVE-2020-26548: Critical severity aviatrix controllers vulnerability
An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any user on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26548?
The severity of CVE-2020-26548 is critical, with a severity value of 8.8.
What is the description of CVE-2020-26548?
CVE-2020-26548 is an issue in Aviatrix Controller where there is an insecure sudo rule that allows a user to execute all commands as any user on the system.
Which version of Aviatrix Controller is affected by CVE-2020-26548?
Aviatrix Controller version 5.3.1516 is affected by CVE-2020-26548.
How can I fix CVE-2020-26548?
To fix CVE-2020-26548, update Aviatrix Controller to version R5.4.1290 or later.
Where can I find more information about CVE-2020-26548?
You can find more information about CVE-2020-26548 at the following link: [https://www.criticalstart.com/multiple-vulnerabilities-discovered-in-aviatrix/](https://www.criticalstart.com/multiple-vulnerabilities-discovered-in-aviatrix/)