Lucene search

K
nvd[email protected]NVD:CVE-2022-38368
HistoryAug 15, 2022 - 10:15 p.m.

CVE-2022-38368

2022-08-1522:15:21
CWE-287
web.nvd.nist.gov
4
authentication
vpn
commandinjection
aviatrixgateway

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

42.8%

An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.

Affected configurations

Nvd
Node
aviatrixgatewayRange<6.6.5712
OR
aviatrixgatewayRange6.7.06.7.1376
VendorProductVersionCPE
aviatrixgateway*cpe:2.3:a:aviatrix:gateway:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

42.8%

Related for NVD:CVE-2022-38368