PT-2020-16453 · Aviatrix · Aviatrix Controller
Published
2020-11-17
·
Updated
2021-07-21
·
CVE-2020-26550
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Aviatrix Controller versions prior to R5.3.1151
Description
An issue was discovered in Aviatrix Controller where an encrypted file containing credentials to unrelated systems is protected by a three-character key.
Recommendations
For Aviatrix Controller versions prior to R5.3.1151, update to version R5.3.1151 or later to resolve the issue.
Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aviatrix Controller