PT-2019-5809 · Aviatrix · Aviatrix Vpn Client
Alex Seymour
·
Published
2019-07-10
·
Updated
2021-09-08
·
CVE-2019-17387
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Aviatrix VPN Client versions through 2.2.10
Description
The issue is related to an authentication flaw in the AVPNC RP service, which can be exploited to gain elevated privileges through arbitrary code execution. This affects Windows, Linux, and macOS systems. The vulnerability is associated with insufficient access control, allowing an attacker to potentially elevate their privileges or execute arbitrary code.
Recommendations
For Aviatrix VPN Client versions through 2.2.10, update to a version later than 2.2.10 to resolve the issue.
At the moment, there is no information about additional mitigation measures for this vulnerability.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aviatrix Vpn Client