CVE-2020-26549

HIGH

Aviatrix Controller <R5.4.1290 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0149
EPSS Percentile 70.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-552
Status published
Products (1)
aviatrix/controller 5.3.1516
Published Nov 17, 2020
Tracked Since Feb 18, 2026