Vulnerabilities > CVE-2020-26548 - Unspecified vulnerability in Aviatrix Controller 5.3.1516

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
aviatrix
critical

Summary

An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any user on the system.

Vulnerable Configurations

Part Description Count
Application
Aviatrix
1