← Back

CVE-2022-38368

nvd nist
Published: Aug 15, 2022Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.

Affected (2)

Products: Aviatrix: Gateway
1 product
Gateway
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Aviatrix
Before 6.6.5712
From 6.7.0 to 6.7.1376

Timeline

No history available yet.