CVE-2020-26549: High severity aviatrix controllers vulnerability
Published Nov 17, 2020
·Updated
An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.
Affected Software
1 affected component
Aviatrix Controller=5.3.1516
Event History
Nov 17, 2020
CVE Published
via MITRE·08:24 PM
Data Sourced
via MITRE·08:24 PM
Description
Frequently Asked Questions
1
What is CVE-2020-26549?
CVE-2020-26549 is a vulnerability in Aviatrix Controller that allows bypassing the htaccess protection mechanism for file downloading.
2
How severe is CVE-2020-26549?
CVE-2020-26549 has a severity rating of 7.5, which is considered high.
3
Which software versions are affected by CVE-2020-26549?
CVE-2020-26549 affects Aviatrix Controller version 5.3.1516.
4
How can I fix CVE-2020-26549?
To fix CVE-2020-26549, update Aviatrix Controller to version R5.4.1290 or later.
5
Where can I find more information about CVE-2020-26549?
More information about CVE-2020-26549 can be found at this link: [https://www.criticalstart.com/multiple-vulnerabilities-discovered-in-aviatrix/](https://www.criticalstart.com/multiple-vulnerabilities-discovered-in-aviatrix/)