Lucene search

K
cveMitreCVE-2022-38368
HistoryAug 15, 2022 - 10:15 p.m.

CVE-2022-38368

2022-08-1522:15:21
CWE-287
mitre
web.nvd.nist.gov
312
7
cve
aviatrix gateway
authentication
vpn
vulnerability
command injection

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

42.8%

An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.

Affected configurations

Nvd
Node
aviatrixgatewayRange<6.6.5712
OR
aviatrixgatewayRange6.7.06.7.1376
VendorProductVersionCPE
aviatrixgateway*cpe:2.3:a:aviatrix:gateway:*:*:*:*:*:*:*:*

Social References

More

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

42.8%

Related for CVE-2022-38368