CVE-2020-27569: High severity aviatrix openvpn vulnerability
Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27569?
CVE-2020-27569 is a vulnerability in Aviatrix VPN Client 2.8.2 and earlier that allows arbitrary file write.
How severe is CVE-2020-27569?
CVE-2020-27569 has a severity score of 7.5 (High).
What software versions are affected by CVE-2020-27569?
Aviatrix VPN Client versions up to and including 2.8.2 are affected by CVE-2020-27569.
How can an attacker exploit CVE-2020-27569?
An attacker can exploit CVE-2020-27569 by leveraging the world-writable log location used by the VPN service to gain write access to any file on the system.
Where can I find more information about CVE-2020-27569?
More information about CVE-2020-27569 can be found at the Aviatrix security bulletin article: [link](https://docs.aviatrix.com/HowTos/security_bulletin_article.html#openvpn-abitrary-file-write)