First published: Wed Apr 21 2021(Updated: )
Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aviatrix OpenVPN | <=2.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27569 is a vulnerability in Aviatrix VPN Client 2.8.2 and earlier that allows arbitrary file write.
CVE-2020-27569 has a severity score of 7.5 (High).
Aviatrix VPN Client versions up to and including 2.8.2 are affected by CVE-2020-27569.
An attacker can exploit CVE-2020-27569 by leveraging the world-writable log location used by the VPN service to gain write access to any file on the system.
More information about CVE-2020-27569 can be found at the Aviatrix security bulletin article: [link](https://docs.aviatrix.com/HowTos/security_bulletin_article.html#openvpn-abitrary-file-write)