Vulnerabilities > CVE-2020-26549 - Files or Directories Accessible to External Parties vulnerability in Aviatrix Controller 5.3.1516

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
aviatrix
CWE-552

Summary

An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.

Vulnerable Configurations

Part Description Count
Application
Aviatrix
1