← Back

Vpn Client

vpn_client

Vendor: Aviatrix • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Aviatrix
1Vpn Client
Nov 21, 2024
Apr 29, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories th...Show more
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.Show less
1Aviatrix
3Controller
GatewayVpn Client
Nov 21, 2024
May 22, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.
1Aviatrix
2Controller
Vpn Client
Nov 21, 2024
May 22, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.
1Aviatrix
1Vpn Client
Nov 21, 2024
Dec 5, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modificatio...Show more
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.Show less
1Aviatrix
1Vpn Client
Nov 21, 2024
Dec 5, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.