PT-2020-13525 · Aviatrix · Aviatrix Controller
Published
2020-05-22
·
Updated
2021-12-01
·
CVE-2020-13413
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Aviatrix Controller versions prior to 5.4.1204
Description
The issue is related to an Observable Response Discrepancy from the API, making it easier to perform user enumeration via brute force. This discrepancy allows attackers to differentiate between existing and non-existing user accounts, facilitating brute-force attacks.
Recommendations
For versions prior to 5.4.1204, update to version 5.4.1204 or later to resolve the issue. As a temporary workaround, consider restricting access to the API to minimize the risk of exploitation. Avoid using the API for user authentication until the issue is resolved.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aviatrix Controller