PT-2019-5809 · Aviatrix · Aviatrix Vpn Client

Alex Seymour

·

Published

2019-07-10

·

Updated

2021-09-08

·

CVE-2019-17387

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aviatrix VPN Client versions through 2.2.10
Description The issue is related to an authentication flaw in the AVPNC RP service, which can be exploited to gain elevated privileges through arbitrary code execution. This affects Windows, Linux, and macOS systems. The vulnerability is associated with insufficient access control, allowing an attacker to potentially elevate their privileges or execute arbitrary code.
Recommendations For Aviatrix VPN Client versions through 2.2.10, update to a version later than 2.2.10 to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02998
CVE-2019-17387

Affected Products

Aviatrix Vpn Client